Compare commits

...
Sign in to create a new pull request.

49 commits

Author SHA1 Message Date
KaiGai Kohei
13d348f335 SE-PostgreSQL was merged into mainstream as contrib/sepgsql extension 2012-04-17 19:05:13 +02:00
Dennis Gilmore
3506cc8b80 - Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild 2012-01-13 21:49:53 -06:00
KaiGai Kohei
81e0ec5839 upgrade base version to 9.0.3, and initial labeling behavior was revised 2011-04-15 09:19:11 +02:00
Dennis Gilmore
61e79cf633 - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild 2011-02-09 07:15:37 -06:00
KaiGai Kohei
723418aa9c upgrade base version v9.0.0->v9.0.1 2010-10-07 10:10:50 +09:00
KaiGai Kohei
73525530cc fixup sepostgresql-9.0-fullset.patch (rebased to the v9.0.0) 2010-10-05 21:40:53 +09:00
KaiGai Kohei
7fe72995be fix specfile 2010-10-05 15:01:10 +09:00
KaiGai Kohei
e3e0f05cda upload postgresql-9.0.0.tar.gz 2010-10-05 14:51:11 +09:00
KaiGai Kohei
aaf1f7379e upgrade base version to 9.0.0 2010-10-05 10:10:56 +09:00
KaiGai Kohei
a2b3668c67 Merge branch 'f13' into f14
Conflicts:
	sepostgresql.init
	sepostgresql.spec
2010-10-05 10:09:19 +09:00
KaiGai Kohei
818aa330e0 upgrade base version to 9.0.0 2010-10-05 10:07:52 +09:00
Fedora Release Engineering
16bcec5b1c dist-git conversion 2010-07-29 12:36:03 +00:00
Fedora Release Engineering
f5d387116f dist-git conversion 2010-07-29 12:35:20 +00:00
KaiGai Kohei
3f75f38b7b add audit-libs-devel on BuildRequires 2010-05-24 13:04:25 +00:00
KaiGai Kohei
1dfef69255 add audit-libs-devel on BuildRequires 2010-05-24 13:03:23 +00:00
KaiGai Kohei
3b2f53bb58 upgrade base version 8.4.3 -> 9.0.0beta1 2010-05-24 12:52:13 +00:00
KaiGai Kohei
25dd9900e6 upgrade base postgresql to 9.0beta1 2010-05-11 14:37:16 +00:00
KaiGai Kohei
9ec59cc87f upgrade base version 8.4.x -> 9.0alpha5 2010-04-03 12:09:31 +00:00
KaiGai Kohei
62301f6c4e upgrade base postgresql 8.4.2->8.4.3 2010-03-18 01:11:03 +00:00
KaiGai Kohei
9657ec6540 upgrade base pgsql 8.4.2->8.4.3 2010-03-18 01:05:00 +00:00
Jesse Keating
e328bd9fdd Initialize branch F-13 for sepostgresql 2010-02-17 03:10:15 +00:00
KaiGai Kohei
7748c46cb9 - fix: build failed due to an implicit header file include
- update: feature backport from v8.5 development
2010-02-15 07:37:21 +00:00
KaiGai Kohei
374d1c5e6e upgrade base version 8.4.1->8.4.2 2009-12-16 13:54:47 +00:00
KaiGai Kohei
478ff226fa - rework: backport features from v8.5devel tree
- fixbug: selinux netlink receiver process didn't have correct ps display
2009-12-08 06:00:14 +00:00
Bill Nottingham
c64ddc4533 Fix typo that causes a failure to update the common directory. (releng
#2781)
2009-11-25 23:15:29 +00:00
KaiGai Kohei
5f922107fd upgrade base PostgreSQL v8.4.0->8.4.1 2009-09-11 10:40:20 +00:00
Tomáš Mráz
1fd93188bc - rebuilt with new openssl 2009-08-21 15:50:34 +00:00
KaiGai Kohei
a9fadaf29f update: sepostgresql-fedora-prefix.patch for 8.4.x and fixes in
sepostgresql.spec
2009-08-19 12:26:11 +00:00
KaiGai Kohei
86c3b96d37 update SE-PostgreSQL to the v8.4.x series 2009-08-19 12:00:30 +00:00
Jesse Keating
9d8091eb0c - Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild 2009-07-27 04:09:56 +00:00
KaiGai Kohei
c57770f45a backport features and bugfixes from v8.4devel tree. 2009-06-09 07:29:38 +00:00
KaiGai Kohei
3fafdfb99e bugfix: /etc/init.d/sepostgresql initdb didn't work correctly 2009-04-17 00:32:23 +00:00
KaiGai Kohei
ec4b913f79 fixes in development policy 2009-03-28 02:23:48 +00:00
KaiGai Kohei
30f6b6e672 - upgrade base PostgreSQL 8.3.6->8.3.7
- backport features from 8.4devel tree
2009-03-27 03:54:13 +00:00
KaiGai Kohei
e11194bd10 bugfix: possible information leak by the order of permission checks in row
level permission checks.
2009-02-26 12:31:05 +00:00
Jesse Keating
16c1abc30f - Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild 2009-02-26 00:29:39 +00:00
KaiGai Kohei
b90dc1fbc8 upgrade base postgresql 8.3.5->8.3.6 2009-02-06 02:34:41 +00:00
Tomáš Mráz
bb36b42241 - rebuild with new openssl 2009-01-18 09:19:10 +00:00
KaiGai Kohei
adf7041c4c fixbug: lack of '#include <sys/stat.h>' at sepgsql/permission.c 2008-11-05 02:09:01 +00:00
KaiGai Kohei
a37bd34768 upgrade base PostgreSQL version 8.3.4->8.3.5 2008-11-05 01:44:05 +00:00
KaiGai Kohei
f3907b871c specfile update. 2008-10-05 08:18:45 +00:00
KaiGai Kohei
db648b3fef - bugfix: "(null)" audit logs for non-cached decision making.
- A hook (pgaceCopyFile) is added for "COPY TO/FROM <file>" cases.
2008-10-02 01:44:40 +00:00
KaiGai Kohei
cdf926f214 upload postgresql-8.3.4.tar.bz2 2008-09-30 03:40:49 +00:00
KaiGai Kohei
7a51097414 update base version to 8.3.4 2008-09-30 03:39:06 +00:00
KaiGai Kohei
5a2d35df72 bugfix: trusted procedure invokation via operators bugfix: FK insertion
with invisible PK cases
2008-09-23 02:04:13 +00:00
KaiGai Kohei
c8d5de8b7d bugfix: trusted procedure invokation 2008-08-13 13:54:49 +00:00
KaiGai Kohei
ba79975f1b update 8.3.x based SE-PostgreSQL which contains backports frmo 8.4devel
tree
2008-07-11 08:39:31 +00:00
KaiGai Kohei
902a2d38d4 - upgrade base PostgreSQL 8.3.1 -> 8.3.3 2008-06-13 04:05:55 +00:00
KaiGai Kohei
51ce27965c - Inconsistent version number format at Changelogs
- BUGFIX: ROW-level control did not work correctly on TRUNCATE
2008-04-30 01:48:38 +00:00
15 changed files with 1 additions and 10653 deletions

View file

@ -1 +0,0 @@
postgresql-8.3.1.tar.bz2

View file

@ -1,21 +0,0 @@
# Makefile for source rpm: sepostgresql
# $Id$
NAME := sepostgresql
SPECFILE = $(firstword $(wildcard *.spec))
define find-makefile-common
for d in common ../common ../../common ; do if [ -f $$d/Makefile.common ] ; then if [ -f $$d/CVS/Root -a -w $$/Makefile.common ] ; then cd $$d ; cvs -Q update ; fi ; echo "$$d/Makefile.common" ; break ; fi ; done
endef
MAKEFILE_COMMON := $(shell $(find-makefile-common))
ifeq ($(MAKEFILE_COMMON),)
# attept a checkout
define checkout-makefile-common
test -f CVS/Root && { cvs -Q -d $$(cat CVS/Root) checkout common && echo "common/Makefile.common" ; } || { echo "ERROR: I can't figure out how to checkout the 'common' module." ; exit -1 ; } >&2
endef
MAKEFILE_COMMON := $(shell $(checkout-makefile-common))
endif
include $(MAKEFILE_COMMON)

1
dead.package Normal file
View file

@ -0,0 +1 @@
SE-PostgreSQL was merged into mainstream as contrib/sepgsql extension

View file

@ -1,87 +0,0 @@
Index: trunk/src/Makefile.global.in
===================================================================
--- trunk/src/Makefile.global.in (revision 430)
+++ trunk/src/Makefile.global.in (working copy)
@@ -73,14 +73,14 @@
datadir := @datadir@
ifeq "$(findstring pgsql, $(datadir))" ""
ifeq "$(findstring postgres, $(datadir))" ""
-override datadir := $(datadir)/postgresql
+override datadir := $(datadir)/sepgsql
endif
endif
sysconfdir := @sysconfdir@
ifeq "$(findstring pgsql, $(sysconfdir))" ""
ifeq "$(findstring postgres, $(sysconfdir))" ""
-override sysconfdir := $(sysconfdir)/postgresql
+override sysconfdir := $(sysconfdir)/sepgsql
endif
endif
@@ -89,7 +89,7 @@
pkglibdir = $(libdir)
ifeq "$(findstring pgsql, $(pkglibdir))" ""
ifeq "$(findstring postgres, $(pkglibdir))" ""
-override pkglibdir := $(pkglibdir)/postgresql
+override pkglibdir := $(pkglibdir)/sepgsql
endif
endif
@@ -98,7 +98,7 @@
pkgincludedir = $(includedir)
ifeq "$(findstring pgsql, $(pkgincludedir))" ""
ifeq "$(findstring postgres, $(pkgincludedir))" ""
-override pkgincludedir := $(pkgincludedir)/postgresql
+override pkgincludedir := $(pkgincludedir)/sepgsql
endif
endif
@@ -109,7 +109,7 @@
ifneq (,$(docdir))
ifeq "$(findstring pgsql, $(docdir))" ""
ifeq "$(findstring postgres, $(docdir))" ""
-override docdir := $(docdir)/postgresql
+override docdir := $(docdir)/sepgsql
endif
endif
endif
Index: trunk/src/bin/pg_ctl/pg_ctl.c
===================================================================
--- trunk/src/bin/pg_ctl/pg_ctl.c (revision 429)
+++ trunk/src/bin/pg_ctl/pg_ctl.c (working copy)
@@ -557,7 +557,7 @@
postmaster_path = pg_malloc(MAXPGPATH);
- if ((ret = find_other_exec(argv0, "postgres", PM_VERSIONSTR,
+ if ((ret = find_other_exec(argv0, "sepostgres", PM_VERSIONSTR,
postmaster_path)) < 0)
{
char full_path[MAXPGPATH];
Index: trunk/src/bin/initdb/initdb.c
===================================================================
--- trunk/src/bin/initdb/initdb.c (revision 429)
+++ trunk/src/bin/initdb/initdb.c (working copy)
@@ -2646,7 +2646,7 @@
sprintf(pgdenv, "PGDATA=%s", pg_data);
putenv(pgdenv);
- if ((ret = find_other_exec(argv[0], "postgres", PG_VERSIONSTR,
+ if ((ret = find_other_exec(argv[0], "sepostgres", PG_VERSIONSTR,
backend_exec)) < 0)
{
char full_path[MAXPGPATH];
Index: trunk/src/bin/pg_dump/pg_dumpall.c
===================================================================
--- trunk/src/bin/pg_dump/pg_dumpall.c (revision 429)
+++ trunk/src/bin/pg_dump/pg_dumpall.c (working copy)
@@ -139,7 +139,7 @@
}
}
- if ((ret = find_other_exec(argv[0], "pg_dump", PGDUMP_VERSIONSTR,
+ if ((ret = find_other_exec(argv[0], "sepg_dump", PGDUMP_VERSIONSTR,
pg_dump_bin)) < 0)
{
char full_path[MAXPGPATH];

View file

@ -1,447 +0,0 @@
diff -rpNU3 pgace/src/bin/pg_dump/pg_dump.c sepgsql/src/bin/pg_dump/pg_dump.c
--- pgace/src/bin/pg_dump/pg_dump.c 2008-02-03 01:18:48.000000000 +0900
+++ sepgsql/src/bin/pg_dump/pg_dump.c 2008-02-03 01:26:35.000000000 +0900
@@ -118,6 +118,9 @@ static int g_numNamespaces;
/* flag to turn on/off dollar quoting */
static int disable_dollar_quoting = 0;
+/* flag to tuen on/off SE-PostgreSQL support */
+#define SELINUX_SYSATTR_NAME "security_context"
+static int enable_selinux = 0;
static void help(const char *progname);
static void expand_schema_name_patterns(SimpleStringList *patterns,
@@ -267,6 +270,7 @@ main(int argc, char **argv)
{"disable-dollar-quoting", no_argument, &disable_dollar_quoting, 1},
{"disable-triggers", no_argument, &disable_triggers, 1},
{"use-set-session-authorization", no_argument, &use_setsessauth, 1},
+ {"enable-selinux", no_argument, &enable_selinux, 1},
{NULL, 0, NULL, 0}
};
@@ -419,6 +423,8 @@ main(int argc, char **argv)
disable_triggers = 1;
else if (strcmp(optarg, "use-set-session-authorization") == 0)
use_setsessauth = 1;
+ else if (strcmp(optarg, "enable-selinux") == 0)
+ enable_selinux = 1;
else
{
fprintf(stderr,
@@ -549,6 +555,24 @@ main(int argc, char **argv)
std_strings = PQparameterStatus(g_conn, "standard_conforming_strings");
g_fout->std_strings = (std_strings && strcmp(std_strings, "on") == 0);
+ if (enable_selinux) {
+ /* confirm whther server support SELinux features */
+ const char *tmp = PQparameterStatus(g_conn, "security_sysattr_name");
+
+ if (!tmp) {
+ write_msg(NULL, "could not get security_sysattr_name from libpq\n");
+ exit(1);
+ }
+ if (!!strcmp(SELINUX_SYSATTR_NAME, tmp) != 0) {
+ write_msg(NULL, "server does not have SELinux feature\n");
+ exit(1);
+ }
+ if (g_fout->remoteVersion < 80204) {
+ write_msg(NULL, "server version is too old (%u)\n", g_fout->remoteVersion);
+ exit(1);
+ }
+ }
+
/* Set the datestyle to ISO to ensure the dump's portability */
do_sql_command(g_conn, "SET DATESTYLE = ISO");
@@ -771,6 +795,7 @@ help(const char *progname)
printf(_(" --use-set-session-authorization\n"
" use SESSION AUTHORIZATION commands instead of\n"
" ALTER OWNER commands to set ownership\n"));
+ printf(_(" --enable-selinux enable to dump security context in SE-PostgreSQL\n"));
printf(_("\nConnection options:\n"));
printf(_(" -h, --host=HOSTNAME database server host or socket directory\n"));
@@ -1160,7 +1185,8 @@ dumpTableData_insert(Archive *fout, void
if (fout->remoteVersion >= 70100)
{
appendPQExpBuffer(q, "DECLARE _pg_dump_cursor CURSOR FOR "
- "SELECT * FROM ONLY %s",
+ "SELECT * %s FROM ONLY %s",
+ (!enable_selinux ? "" : "," SELINUX_SYSATTR_NAME),
fmtQualifiedId(tbinfo->dobj.namespace->dobj.name,
classname));
}
@@ -1774,11 +1800,32 @@ dumpBlobComments(Archive *AH, void *arg)
Oid blobOid;
char *comment;
+ blobOid = atooid(PQgetvalue(res, i, 0));
+
+ /* dump security context of binary large object */
+ if (enable_selinux) {
+ PGresult *__res;
+ char query[512];
+
+ snprintf(query, sizeof(query),
+ "SELECT lo_get_security(%u)", blobOid);
+ __res = PQexec(g_conn, query);
+ check_sql_result(__res, g_conn, query, PGRES_TUPLES_OK);
+
+ if (PQntuples(__res) != 1) {
+ write_msg(NULL, "lo_get_security(%u) returns %d tuples\n",
+ blobOid, PQntuples(__res));
+ exit_nicely();
+ }
+ archprintf(AH, "SELECT lo_set_security(%u, '%s');\n",
+ blobOid, PQgetvalue(__res, 0, 0));
+ PQclear(__res);
+ }
+
/* ignore blobs without comments */
if (PQgetisnull(res, i, 1))
continue;
- blobOid = atooid(PQgetvalue(res, i, 0));
comment = PQgetvalue(res, i, 1);
printfPQExpBuffer(commentcmd, "COMMENT ON LARGE OBJECT %u IS ",
@@ -2886,6 +2933,7 @@ getTables(int *numTables)
int i_owning_col;
int i_reltablespace;
int i_reloptions;
+ int i_selinux;
/* Make sure we are in proper schema */
selectSourceSchema("pg_catalog");
@@ -2926,6 +2974,7 @@ getTables(int *numTables)
"d.refobjsubid as owning_col, "
"(SELECT spcname FROM pg_tablespace t WHERE t.oid = c.reltablespace) AS reltablespace, "
"array_to_string(c.reloptions, ', ') as reloptions "
+ "%s "
"from pg_class c "
"left join pg_depend d on "
"(c.relkind = '%c' and "
@@ -2935,6 +2984,7 @@ getTables(int *numTables)
"where relkind in ('%c', '%c', '%c', '%c') "
"order by c.oid",
username_subquery,
+ (!enable_selinux ? "" : ",c." SELINUX_SYSATTR_NAME),
RELKIND_SEQUENCE,
RELKIND_RELATION, RELKIND_SEQUENCE,
RELKIND_VIEW, RELKIND_COMPOSITE_TYPE);
@@ -3101,6 +3151,7 @@ getTables(int *numTables)
i_owning_col = PQfnumber(res, "owning_col");
i_reltablespace = PQfnumber(res, "reltablespace");
i_reloptions = PQfnumber(res, "reloptions");
+ i_selinux = PQfnumber(res, SELINUX_SYSATTR_NAME);
for (i = 0; i < ntups; i++)
{
@@ -3131,6 +3182,9 @@ getTables(int *numTables)
}
tblinfo[i].reltablespace = strdup(PQgetvalue(res, i, i_reltablespace));
tblinfo[i].reloptions = strdup(PQgetvalue(res, i, i_reloptions));
+ tblinfo[i].relsecurity = NULL;
+ if (i_selinux >= 0)
+ tblinfo[i].relsecurity = strdup(PQgetvalue(res, i, i_selinux));
/* other fields were zeroed above */
@@ -4319,6 +4373,7 @@ getTableAttrs(TableInfo *tblinfo, int nu
int i_atthasdef;
int i_attisdropped;
int i_attislocal;
+ int i_attselinux;
PGresult *res;
int ntups;
bool hasdefaults;
@@ -4362,11 +4417,13 @@ getTableAttrs(TableInfo *tblinfo, int nu
appendPQExpBuffer(q, "SELECT a.attnum, a.attname, a.atttypmod, a.attstattarget, a.attstorage, t.typstorage, "
"a.attnotnull, a.atthasdef, a.attisdropped, a.attislocal, "
"pg_catalog.format_type(t.oid,a.atttypmod) as atttypname "
+ "%s " /* security context, if required */
"from pg_catalog.pg_attribute a left join pg_catalog.pg_type t "
"on a.atttypid = t.oid "
"where a.attrelid = '%u'::pg_catalog.oid "
"and a.attnum > 0::pg_catalog.int2 "
"order by a.attrelid, a.attnum",
+ (!enable_selinux ? "" : ",a." SELINUX_SYSATTR_NAME),
tbinfo->dobj.catId.oid);
}
else if (g_fout->remoteVersion >= 70100)
@@ -4415,6 +4472,7 @@ getTableAttrs(TableInfo *tblinfo, int nu
i_atthasdef = PQfnumber(res, "atthasdef");
i_attisdropped = PQfnumber(res, "attisdropped");
i_attislocal = PQfnumber(res, "attislocal");
+ i_attselinux = PQfnumber(res, SELINUX_SYSATTR_NAME);
tbinfo->numatts = ntups;
tbinfo->attnames = (char **) malloc(ntups * sizeof(char *));
@@ -4425,6 +4483,7 @@ getTableAttrs(TableInfo *tblinfo, int nu
tbinfo->typstorage = (char *) malloc(ntups * sizeof(char));
tbinfo->attisdropped = (bool *) malloc(ntups * sizeof(bool));
tbinfo->attislocal = (bool *) malloc(ntups * sizeof(bool));
+ tbinfo->attsecurity = (char **) malloc(ntups * sizeof(char *));
tbinfo->notnull = (bool *) malloc(ntups * sizeof(bool));
tbinfo->attrdefs = (AttrDefInfo **) malloc(ntups * sizeof(AttrDefInfo *));
tbinfo->inhAttrs = (bool *) malloc(ntups * sizeof(bool));
@@ -4456,6 +4515,11 @@ getTableAttrs(TableInfo *tblinfo, int nu
tbinfo->inhAttrs[j] = false;
tbinfo->inhAttrDef[j] = false;
tbinfo->inhNotNull[j] = false;
+
+ /* security attribute, if defined */
+ tbinfo->attsecurity[j] = NULL;
+ if (i_attselinux >= 0 && !PQgetisnull(res, j, i_attselinux))
+ tbinfo->attsecurity[j] = strdup(PQgetvalue(res, j, i_attselinux));
}
PQclear(res);
@@ -6428,6 +6492,7 @@ dumpFunc(Archive *fout, FuncInfo *finfo)
char *proconfig;
char *procost;
char *prorows;
+ char *proselinux = NULL;
char *lanname;
char *rettypename;
int nallargs;
@@ -6459,8 +6524,10 @@ dumpFunc(Archive *fout, FuncInfo *finfo)
"provolatile, proisstrict, prosecdef, "
"proconfig, procost, prorows, "
"(SELECT lanname FROM pg_catalog.pg_language WHERE oid = prolang) as lanname "
+ "%s " /* security context, if required */
"FROM pg_catalog.pg_proc "
"WHERE oid = '%u'::pg_catalog.oid",
+ (!enable_selinux ? "" : "," SELINUX_SYSATTR_NAME),
finfo->dobj.catId.oid);
}
else if (g_fout->remoteVersion >= 80100)
@@ -6562,6 +6629,13 @@ dumpFunc(Archive *fout, FuncInfo *finfo)
prorows = PQgetvalue(res, 0, PQfnumber(res, "prorows"));
lanname = PQgetvalue(res, 0, PQfnumber(res, "lanname"));
+ if (enable_selinux) {
+ int i_selinux = PQfnumber(res, "security_context");
+
+ if (i_selinux >= 0 && !PQgetisnull(res, 0, i_selinux))
+ proselinux = PQgetvalue(res, 0, i_selinux);
+ }
+
/*
* See backend/commands/define.c for details of how the 'AS' clause is
* used.
@@ -6698,6 +6772,9 @@ dumpFunc(Archive *fout, FuncInfo *finfo)
if (prosecdef[0] == 't')
appendPQExpBuffer(q, " SECURITY DEFINER");
+ if (proselinux)
+ appendPQExpBuffer(q, " CONTEXT = '%s'", proselinux);
+
/*
* COST and ROWS are emitted only if present and not default, so as not to
* break backwards-compatibility of the dump without need. Keep this code
@@ -8779,6 +8856,9 @@ dumpTableSchema(Archive *fout, TableInfo
if (tbinfo->notnull[j] && !tbinfo->inhNotNull[j])
appendPQExpBuffer(q, " NOT NULL");
+ if (enable_selinux && tbinfo->attsecurity[j])
+ appendPQExpBuffer(q, " CONTEXT = '%s'", tbinfo->attsecurity[j]);
+
actual_atts++;
}
}
@@ -8826,6 +8906,9 @@ dumpTableSchema(Archive *fout, TableInfo
if (tbinfo->reloptions && strlen(tbinfo->reloptions) > 0)
appendPQExpBuffer(q, "\nWITH (%s)", tbinfo->reloptions);
+ if (enable_selinux && tbinfo->relsecurity)
+ appendPQExpBuffer(q, " CONTEXT = '%s'", tbinfo->relsecurity);
+
appendPQExpBuffer(q, ";\n");
/* Loop dumping statistics and storage statements */
@@ -10243,6 +10326,12 @@ fmtCopyColumnList(const TableInfo *ti)
appendPQExpBuffer(q, "(");
needComma = false;
+
+ if (enable_selinux) {
+ appendPQExpBuffer(q, SELINUX_SYSATTR_NAME);
+ needComma = true;
+ }
+
for (i = 0; i < numatts; i++)
{
if (attisdropped[i])
diff -rpNU3 pgace/src/bin/pg_dump/pg_dump.h sepgsql/src/bin/pg_dump/pg_dump.h
--- pgace/src/bin/pg_dump/pg_dump.h 2008-01-08 01:39:49.000000000 +0900
+++ sepgsql/src/bin/pg_dump/pg_dump.h 2008-01-10 18:25:12.000000000 +0900
@@ -238,6 +238,7 @@ typedef struct _tableInfo
char relkind;
char *reltablespace; /* relation tablespace */
char *reloptions; /* options specified by WITH (...) */
+ char *relsecurity; /* security attribute of the relation */
bool hasindex; /* does it have any indexes? */
bool hasrules; /* does it have any rules? */
bool hasoids; /* does it have OIDs? */
@@ -262,6 +263,7 @@ typedef struct _tableInfo
char *typstorage; /* type storage scheme */
bool *attisdropped; /* true if attr is dropped; don't dump it */
bool *attislocal; /* true if attr has local definition */
+ char **attsecurity; /* security attribute of attribute (column) */
/*
* Note: we need to store per-attribute notnull, default, and constraint
diff -rpNU3 pgace/src/bin/pg_dump/pg_dumpall.c sepgsql/src/bin/pg_dump/pg_dumpall.c
--- pgace/src/bin/pg_dump/pg_dumpall.c 2008-01-08 01:39:49.000000000 +0900
+++ sepgsql/src/bin/pg_dump/pg_dumpall.c 2008-01-10 18:25:12.000000000 +0900
@@ -67,6 +67,10 @@ static int disable_triggers = 0;
static int use_setsessauth = 0;
static int server_version;
+/* flag to tuen on/off SE-PostgreSQL support */
+#define SELINUX_SYSATTR_NAME "security_context"
+static int enable_selinux = 0;
+
static FILE *OPF;
static char *filename = NULL;
@@ -119,6 +123,7 @@ main(int argc, char *argv[])
{"disable-dollar-quoting", no_argument, &disable_dollar_quoting, 1},
{"disable-triggers", no_argument, &disable_triggers, 1},
{"use-set-session-authorization", no_argument, &use_setsessauth, 1},
+ {"enable-selinux", no_argument, NULL, 1001},
{NULL, 0, NULL, 0}
};
@@ -290,6 +295,10 @@ main(int argc, char *argv[])
appendPQExpBuffer(pgdumpopts, " --disable-triggers");
else if (strcmp(optarg, "use-set-session-authorization") == 0)
/* no-op, still allowed for compatibility */ ;
+ else if (strcmp(optarg, "enable-selinux") == 0) {
+ appendPQExpBuffer(pgdumpopts, " --enable-selinux");
+ enable_selinux = 1;
+ }
else
{
fprintf(stderr,
@@ -300,6 +309,11 @@ main(int argc, char *argv[])
}
break;
+ case 1001:
+ appendPQExpBuffer(pgdumpopts, " --enable-selinux");
+ enable_selinux = 1;
+ break;
+
case 0:
break;
@@ -391,6 +405,24 @@ main(int argc, char *argv[])
}
}
+ if (enable_selinux) {
+ /* confirm whther server support SELinux features */
+ const char *tmp = PQparameterStatus(conn, "security_sysattr_name");
+
+ if (!tmp) {
+ fprintf(stderr, "could not get security_sysattr_name from libpq\n");
+ exit(1);
+ }
+ if (!!strcmp(SELINUX_SYSATTR_NAME, tmp) != 0) {
+ fprintf(stderr, "server does not have SELinux feature\n");
+ exit(1);
+ }
+ if (server_version < 80204) {
+ fprintf(stderr, "server version is too old (%u)\n", server_version);
+ exit(1);
+ }
+ }
+
/*
* Open the output file if required, otherwise use stdout
*/
@@ -505,6 +537,7 @@ help(void)
printf(_(" --use-set-session-authorization\n"
" use SESSION AUTHORIZATION commands instead of\n"
" OWNER TO commands\n"));
+ printf(_(" --enable-selinux enable to dump security attribute\n"));
printf(_("\nConnection options:\n"));
printf(_(" -h, --host=HOSTNAME database server host or socket directory\n"));
@@ -915,16 +948,18 @@ dumpCreateDB(PGconn *conn)
fprintf(OPF, "--\n-- Database creation\n--\n\n");
if (server_version >= 80100)
- res = executeQuery(conn,
+ appendPQExpBuffer(buf,
"SELECT datname, "
"coalesce(rolname, (select rolname from pg_authid where oid=(select datdba from pg_database where datname='template0'))), "
"pg_encoding_to_char(d.encoding), "
"datistemplate, datacl, datconnlimit, "
"(SELECT spcname FROM pg_tablespace t WHERE t.oid = d.dattablespace) AS dattablespace "
+ "%s "
"FROM pg_database d LEFT JOIN pg_authid u ON (datdba = u.oid) "
- "WHERE datallowconn ORDER BY 1");
+ "WHERE datallowconn ORDER BY 1",
+ (!enable_selinux ? "" : "d." SELINUX_SYSATTR_NAME));
else if (server_version >= 80000)
- res = executeQuery(conn,
+ appendPQExpBuffer(buf,
"SELECT datname, "
"coalesce(usename, (select usename from pg_shadow where usesysid=(select datdba from pg_database where datname='template0'))), "
"pg_encoding_to_char(d.encoding), "
@@ -933,7 +968,7 @@ dumpCreateDB(PGconn *conn)
"FROM pg_database d LEFT JOIN pg_shadow u ON (datdba = usesysid) "
"WHERE datallowconn ORDER BY 1");
else if (server_version >= 70300)
- res = executeQuery(conn,
+ appendPQExpBuffer(buf,
"SELECT datname, "
"coalesce(usename, (select usename from pg_shadow where usesysid=(select datdba from pg_database where datname='template0'))), "
"pg_encoding_to_char(d.encoding), "
@@ -942,7 +977,7 @@ dumpCreateDB(PGconn *conn)
"FROM pg_database d LEFT JOIN pg_shadow u ON (datdba = usesysid) "
"WHERE datallowconn ORDER BY 1");
else if (server_version >= 70100)
- res = executeQuery(conn,
+ appendPQExpBuffer(buf,
"SELECT datname, "
"coalesce("
"(select usename from pg_shadow where usesysid=datdba), "
@@ -958,7 +993,7 @@ dumpCreateDB(PGconn *conn)
* Note: 7.0 fails to cope with sub-select in COALESCE, so just deal
* with getting a NULL by not printing any OWNER clause.
*/
- res = executeQuery(conn,
+ appendPQExpBuffer(buf,
"SELECT datname, "
"(select usename from pg_shadow where usesysid=datdba), "
"pg_encoding_to_char(d.encoding), "
@@ -968,6 +1003,7 @@ dumpCreateDB(PGconn *conn)
"FROM pg_database d "
"ORDER BY 1");
}
+ res = executeQuery(conn, buf->data);
for (i = 0; i < PQntuples(res); i++)
{
@@ -978,6 +1014,7 @@ dumpCreateDB(PGconn *conn)
char *dbacl = PQgetvalue(res, i, 4);
char *dbconnlimit = PQgetvalue(res, i, 5);
char *dbtablespace = PQgetvalue(res, i, 6);
+ char *dbsecurity = PQgetvalue(res, i, 7);
char *fdbname;
fdbname = strdup(fmtId(dbname));
@@ -1021,6 +1058,9 @@ dumpCreateDB(PGconn *conn)
appendPQExpBuffer(buf, " CONNECTION LIMIT = %s",
dbconnlimit);
+ if (enable_selinux && dbsecurity)
+ appendPQExpBuffer(buf, " CONTEXT = '%s'", dbsecurity);
+
appendPQExpBuffer(buf, ";\n");
if (strcmp(dbistemplate, "t") == 0)

File diff suppressed because it is too large Load diff

File diff suppressed because it is too large Load diff

View file

@ -1,100 +0,0 @@
.TH "sepostgresql" "8" "Jul 15 2007" "kaigai@kaigai.gr.jp" "Security-Enhanced PostgreSQL"
.SH "NAME"
sepostgresql \- Security-Enhances PostgreSQL
.SH "DESCRIPTION"
Security-Enhanced PostgreSQL (SE-PostgreSQL) is an enhancement of PostgreSQL, to apply fine grained mandatory access control for database objects based on the security policy of SELinux.
These features enable to apply flexible integrated access control policy between operating system and database management system, during all stages of the life of the information.
.PP
This document describes the way to customize SE-PostgreSQL on the default security policy.
.SH "BOOLEANS"
The SELinux policy is customizable via BOOLEAN variable. This variable has two states, 1 (on) or 0 (off). A part of the policy is enabled or disabled depending on related boolean variables.
\fBsepgsql_enable_unconfined\fP toggles whether \fIunconfined_t\fP and \fIsysadm_t\fP domains are allowed to access database objects without any restruction on type enforcement, or not.
When \fIsepgsql_enable_unconfined\fP is off, those domains are also restricted its operation as other domains begin applied. In the default, it is set to on.
You can set it as follows:
.EX
setsebool -P sepgsql_enable_unconfined ( \fBon\fP | off )
.EE
\fBsepgsql_enable_users_ddl\fP toggles whether non-administrative domain is allowed to use DDL statement like CREATE TABLE and so on.
In the default, it is set to on. You can set it as follows:
.EX
setsebool -P sepgsql_enable_users_ddl ( \fBon\fP | off )
.EE
\fBsepgsql_enable_auditallow\fP toggles output of audit messages in the case when required permission checks are allowed. In the default, it is set to off. You can set it as follows:
.EX
setsebool -P sepgsql_enable_auditallow ( on | \fBoff\fP )
.EE
\fBsepgsql_enable_auditdeny\fP toggles output of audit messages in the case when required permission checks are denied. In the default, it is set to on. You can set it as follows:
.EX
setsebool -P sepgsql_enable_auditdeny ( \fBon\fP | off )
.EE
\fBsepgsql_enable_audittuple\fP toggles output of audit messages for any tuple. Because audit messages for tuples in a large size table can cause flood of messages, we can set \fIsepgsql_enable_audittuple\fP independently from any other object classes.
Audit messages for tuples are generated in the only case when \fIsepgsql_enable_audittuple\fP and either \fIsepgsql_enable_auditallow\fP or \fIsepgsql_enable_auditdeny\fP are enabled.
In the default, it is set to off. You can set it as follows:
.EX
setsebool -P sepgsql_enable_audittuple ( on | \fBoff\fP )
.EE
.SH "TYPES"
\fBsepgsql_db_t\fP is a only type for database itself.
It is attched for newly created databases in the default.
\fBsepgsql_table_t\fP is a type for tables, columns and tuples.
It is attached for newly created the objects in the default.
Non-administrative clients can do any kinds of operations except for relabeling.
\fBsepgsql_secret_table_t\fP is a type for tables, columns and tuples.
Non-administrative clients cannot access the objects with this type.
\fBsepgsql_ro_table_t\fP is a type for read-only tables, columns and tuples.
Non-administrative clients cannot modify the objects with this type.
\fBsepgsql_fixed_table_t\fP is a type for non-manupulatable tables, columns and tuples.
Non-administrative clients cannot update or delete the objects with this type.
\fBsepgsql_proc_t\fP is a type for procedures.
It is attached for newly created procedures by adminictrative domain.
Any client can call these procedures with this type.
\fBsepgsql_userproc_t\fP is a type for procedures.
It is attached for newly created procedures by non-administrative domain.
Administrative domains cannot call the procedure for safety. He have to relabel it into \fIsepgsql_proc_t\fP at first. It is a policy to avoid to execute doubtful code under administrative domain.
\fBsepgsql_trusted_proc_t\fP is a type for trusted procedures.
Calling procedures with this type invokes domain transition.
Then the function works as an administrative domain, so database administrator can provide limited path to access protected object.
\fBsepgsql_blob_t\fP is a type for binary large objects (blob).
It is attached for newly created blob in the default.
Non-administrative clients can read and write the blobs with this type.
\fBsepgsql_ro_blob_t\fP is a type for read-only binary large objects (blob).
Non-administrative clients cannot write the blobs with this type.
.SH "BACKUP and RESTORE"
\fI--enable-selinux\fP option in \fBsepg_dump\fP and \fBsepg_dumpall\fP enable to dump database image with security context. We can restore the dumped image using the standard \fIpg_restore\fP and so on.
.EX
Example)
$ sepg_dump -Ft -b --enable-selinux postgres | gzip -c > postgres.tgz
.EE
.SH AUTHOR
This manual page was written by KaiGai Kohei <kaigai@kaigai.gr.jp>
.SH "SEE ALSO"
selinux(8), boolean(8)

View file

@ -1,10 +0,0 @@
#
# SE-PostgreSQL install path
#
/usr/bin/sepostgres -- gen_context(system_u:object_r:postgresql_exec_t,s0)
/usr/bin/initdb.sepgsql -- gen_context(system_u:object_r:postgresql_exec_t,s0)
/usr/bin/sepg_ctl -- gen_context(system_u:object_r:initrc_exec_t,s0)
/var/lib/sepgsql(/.*)? gen_context(system_u:object_r:postgresql_db_t,s0)
/var/lib/sepgsql/pgstartup\.log gen_context(system_u:object_r:postgresql_log_t,s0)
/var/log/sepostgresql\.log.* -- gen_context(system_u:object_r:postgresql_log_t,s0)

View file

@ -1,88 +0,0 @@
########################################
## <summary>
## Marks the specified domain as SE-PostgreSQL server process.
## </summary>
## <param name="domain">
## <summary>
## Domain to be marked
## </summary>
## </param>
#
interface(`sepgsql_server_domain',`
gen_require(`
attribute sepgsql_server_type;
')
typeattribute $1 sepgsql_server_type;
')
########################################
## <summary>
## Allow the specified domain unconfined accesses to any database objects
## managed by SE-PostgreSQL,
## </summary>
## <param name="domain">
## <summary>
## Domain allowed access.
## </summary>
## </param>
#
interface(`sepgsql_unconfined_domain',`
gen_require(`
attribute sepgsql_unconfined_type;
attribute sepgsql_client_type;
')
typeattribute $1 sepgsql_unconfined_type;
typeattribute $1 sepgsql_client_type;
')
########################################
## <summary>
## Allow the specified domain unprivileged accesses to any database objects
## managed by SE-PostgreSQL,
## </summary>
## <param name="domain">
## <summary>
## Domain allowed access.
## </summary>
## </param>
#
interface(`sepgsql_client_domain',`
gen_require(`
attribute sepgsql_client_type;
')
typeattribute $1 sepgsql_client_type;
')
########################################
## <summary>
## Allow the specified role to invoke trusted procedures
## </summary>
## <param name="role">
## <summary>
## The role associated with the domain.
## </summary>
## </param>
#
interface(`sepgsql_trusted_procedure_role',`
gen_require(`
type sepgsql_trusted_domain_t;
')
role $1 types sepgsql_trusted_domain_t;
')
########################################
## <summary>
## Marks as a SE-PostgreSQL loadable shared library module
## </summary>
## <param name="type">
## <summary>
## Type marked as a database object type.
## </summary>
## </param>
#
interface(`sepgsql_loadable_module',`
gen_require(`
attribute sepgsql_module_type;
')
typeattribute $1 sepgsql_module_type;
')

View file

@ -1,213 +0,0 @@
#!/bin/sh
# sepostgresql This is the init script for starting up SE-PostgreSQL
#
# chkconfig: - 62 38
# description: Starts and stops the SE-PostgreSQL backend daemon
# processname: postmaster
# pidfile: /var/run/postmaster.pid
#---------------------------------------------------------------------
PGVERSION="8.3.1"
PGMAJORVERSION=`echo "$PGVERSION" | sed 's/^\([0-9]*\.[0-9a-z]*\).*$/\1/'`
SEPGVERSION="2.179"
# source function library
. /etc/rc.d/init.d/functions
# get config
. /etc/sysconfig/network
# find the name of the script
NAME=`basename $0`
if [ ${NAME:0:1} = "S" -o ${NAME:0:1} = "K" ]; then
NAME=${NAME:3}
fi
# set defaults for configurable variables
SEPGSQL_BIN="/usr/bin"
SEPGSQL_DATA="/var/lib/sepgsql/data"
SEPGSQL_OPTS="-i -p 5432"
SEPGSQL_STARTUP_LOG="/var/lib/sepgsql/pgstartup.log"
SEPGSQL_LOG="/var/log/sepostgresql.log"
SEPGSQL_FALLBACK_CONTEXT="user_u:user_r:user_t"
# override defaults from /etc/sysconfig/sepostgresql
test -f /etc/sysconfig/${NAME} && . /etc/sysconfig/${NAME}
export SEPGSQL_FALLBACK_CONTEXT
# Check that networking is up.
test "${NETWORKING}" = "no" && exit 0
test -f "${SEPGSQL_BIN}/postmaster" || exit 1
script_result=0
do_start() {
PSQL_START=$"Starting ${NAME} service: "
echo -n "$PSQL_START"
# make sure startup-time log file is valid
if [ ! -e "${SEPGSQL_STARTUP_LOG}" -a ! -h "${SEPGSQL_STARTUP_LOG}" ]; then
touch "${SEPGSQL_STARTUP_LOG}" || exit 1
chown sepgsql:sepgsql "${SEPGSQL_STARTUP_LOG}"
chmod 600 "${SEPGSQL_STARTUP_LOG}"
/sbin/restorecon "${SEPGSQL_STARTUP_LOG}"
fi
# check for the SEPGSQL_DATA structure
if [ -f "${SEPGSQL_DATA}/PG_VERSION" ] && [ -d "${SEPGSQL_DATA}/base" ]; then
if [ x`cat "${SEPGSQL_DATA}/PG_VERSION"` != x"${PGMAJORVERSION}" ]; then
echo_failure
echo
echo "HINT: An old version of the database format was found."
echo "HINT: You need to upgrade the data format before using SE-PostgreSQL."
exit 1
fi
else
echo_failure
echo
echo "HINT: ${SEPGSQL_DATA} is missing."
echo "HINT: Use '/etc/init.d/${NAME} initdb'"
echo "HINT: to initialize the database cluster first."
exit 1
fi
# make sure SEPGSQL_LOG
touch ${SEPGSQL_LOG}
chown sepgsql:sepgsql ${SEPGSQL_LOG}
chmod 600 ${SEPGSQL_LOG}
test -x /sbin/restorecon && /sbin/restorecon ${SEPGSQL_LOG}
cd ${SEPGSQL_BIN}
/sbin/runuser sepgsql -c "./sepg_ctl -l ${SEPGSQL_LOG} -D ${SEPGSQL_DATA} -o '${SEPGSQL_OPTS}' start" \
>> ${SEPGSQL_STARTUP_LOG} 2>&1 < /dev/null
sleep 1
PID=`/sbin/runuser sepgsql -c "./sepg_ctl -D ${SEPGSQL_DATA} status 2>/dev/null \
| sed 's/^.*PID: //g' | sed 's/[^0-9].*$//g'"`
if [ ${PIPESTATUS[0]} -eq 0 ]; then
echo "$PID" > "/var/run/${NAME}.pid"
touch "/var/lock/subsys/${NAME}.lock"
echo_success
else
script_result=1
echo_failure
fi
echo
}
do_stop() {
echo -n $"Stopping ${NAME} service: "
cd ${SEPGSQL_BIN}
/sbin/runuser sepgsql -c "./sepg_ctl -D ${SEPGSQL_DATA} stop" \
>> ${SEPGSQL_STARTUP_LOG} 2>&1 < /dev/null
ret=$?
if [ $ret -eq 0 ]; then
echo_success
else
echo_failure
script_result=1
fi
echo
rm -f "/var/run/${NAME}.pid"
rm -f "/var/lock/subsys/${NAME}.lock"
}
do_status() {
cd ${SEPGSQL_BIN}
/sbin/runuser sepgsql -- -c "./sepg_ctl -D ${SEPGSQL_DATA} status" 2>/dev/null \
| head -1 | sed "s/^sepg_ctl:/${NAME}:/g"
if [ ${PIPESTATUS[0]} -ne 0 ]; then
script_result=3
test -e "/var/run/${NAME}.pid" && script_result=1
test -e "/var/lock/subsys/${NAME}.lock" && script_result=2
fi
}
do_condrestart() {
cd ${SEPGSQL_BIN}
/sbin/runuser sepgsql -- -c "./sepg_ctl -D ${SEPGSQL_DATA} status" &>/dev/null && do_stop && do_start
}
do_condstop() {
cd ${SEPGSQL_BIN}
/sbin/runuser sepgsql -- -c "./sepg_ctl -D ${SEPGSQL_DATA} status" &>/dev/null && do_stop
}
do_reload() {
echo -n $"Reloading ${NAME} service: "
cd ${SEPGSQL_BIN}
/sbin/runuser sepgsql -- -c "./sepg_ctl -D ${SEPGSQL_DATA} reload" &>/dev/null < /dev/null
if [ $? -eq 0 ]; then
echo_success
else
echo_failure
script_result=1
fi
echo
}
do_initdb() {
echo -n $"Initializing database: "
if [ -f "${SEPGSQL_DATA}/PG_VERSION" ]; then
echo_failure
echo
echo "HINT: Data directory is not empty"
script_result=1
else
if [ ! -e "${SEPGSQL_DATA}" -a ! -h "${SEPGSQL_DATA}" ]; then
mkdir -p "${SEPGSQL_DATA}" || exit 1
chown sepgsql:sepgsql "${SEPGSQL_DATA}"
chmod 600 "${SEPGSQL_DATA}"
fi
# cleanup SELinux labeling for "${SEPGSQL_DATA}"
test -x /sbin/restorecon && /sbin/restorecon -R "${SEPGSQL_DATA}"
# Initialize the database
cd ${SEPGSQL_BIN}
/sbin/runuser -- sepgsql -c "./initdb.sepgsql -A 'ident sameuser' ${SEPGSQL_DATA}" \
>> "${SEPGSQL_STARTUP_LOG}" 2>&1 < /dev/null
if [ -f "${SEPGSQL_DATA}/PG_VERSION" ]; then
echo_success
else
echo_failure
script_result=1
fi
echo
fi
}
# see how we were called.
case "$1" in
start)
do_start
;;
stop)
do_stop
;;
status)
do_status
;;
restart)
do_stop
do_start
;;
condrestart)
do_condrestart
;;
condstop)
do_condstop
;;
reload|force-reload)
do_reload
;;
initdb)
do_initdb
;;
*)
echo $"Usage: $0 {start|stop|status|restart|condrestart|condstop|reload|force-reload|initdb}"
exit 1
;;
esac
exit $script_result

View file

@ -1,11 +0,0 @@
# logrotate configuration for SE-PostgreSQL
/var/log/sepostgresql.log {
rotate 4
compress
size 4M
notifempty
postrotate
/sbin/service sepostgresql restart >& /dev/null
endscript
}

View file

@ -1,404 +0,0 @@
#
# Security Enhanced PostgreSQL (SE-PostgreSQL)
#
# Copyright 2007 KaiGai Kohei <kaigai@kaigai.gr.jp>
# -----------------------------------------------------
# SELinux policy types
%define selinux_variants mls strict targeted
# SE-PostgreSQL status extension
Summary: Security Enhanced PostgreSQL
Name: sepostgresql
Version: 8.3.1
Release: 2.179%{?sepgsql_extension}%{?dist}
License: BSD
Group: Applications/Databases
Url: http://code.google.com/p/sepgsql/
Buildroot: %(mktemp -ud %{_tmppath}/%{name}-%{version}-%{release}-XXXXXX)
Source0: ftp://ftp.postgresql.org/pub/source/v%{version}/postgresql-%{version}.tar.bz2
Source1: sepostgresql.init
Source2: sepostgresql.if
Source3: sepostgresql.te
Source4: sepostgresql.fc
Source5: sepostgresql.8
Source6: sepostgresql.logrotate
Patch0: sepostgresql-pgace-8.3.1-2.patch
Patch1: sepostgresql-sepgsql-8.3.1-2.patch
Patch2: sepostgresql-pg_dump-8.3.1-2.patch
Patch3: sepostgresql-fedora-prefix.patch
BuildRequires: perl glibc-devel bison flex readline-devel zlib-devel >= 1.0.4
Buildrequires: checkpolicy libselinux-devel >= 2.0.43 selinux-policy-devel selinux-policy >= 3.0.6
Requires(pre): shadow-utils
Requires(post): policycoreutils /sbin/chkconfig
Requires(preun): /sbin/chkconfig /sbin/service
Requires(postun): policycoreutils
Requires: postgresql-server = %{version}
Requires: policycoreutils >= 2.0.16 libselinux >= 2.0.43 selinux-policy >= 3.0.6
Requires: tzdata logrotate
%description
Security Enhanced PostgreSQL is an extension of PostgreSQL
based on SELinux security policy, that applies fine grained
mandatory access control to many objects within the database,
and takes advantage of user authorization integrated within
the operating system. SE-PostgreSQL works as a userspace
reference monitor to check any SQL query.
%prep
%setup -q -n postgresql-%{version}
%patch0 -p1
%patch1 -p1
%patch2 -p1
%patch3 -p1
mkdir selinux-policy
cp -p %{SOURCE2} %{SOURCE3} %{SOURCE4} selinux-policy
%build
CFLAGS="${CFLAGS:-%optflags}" ; export CFLAGS
CXXFLAGS="${CXXFLAGS:-%optflags}" ; export CXXFLAGS
# build Binary Policy Module
pushd selinux-policy
for selinuxvariant in %{selinux_variants}
do
make NAME=${selinuxvariant} -f %{_datadir}/selinux/devel/Makefile
mv %{name}.pp %{name}.pp.${selinuxvariant}
make NAME=${selinuxvariant} -f %{_datadir}/selinux/devel/Makefile clean
done
popd
# build SE-PostgreSQL
%configure --disable-rpath \
--enable-selinux \
%if %{defined sepgextension}
--enable-debug \
--enable-cassert \
%endif
--libdir=%{_libdir}/pgsql \
--datadir=%{_datadir}/sepgsql \
--with-system-tzdata=/usr/share/zoneinfo
# parallel build, if possible
make %{?_smp_mflags}
%install
rm -rf %{buildroot}
pushd selinux-policy
for selinuxvariant in %{selinux_variants}
do
install -d %{buildroot}%{_datadir}/selinux/${selinuxvariant}
install -p -m 644 %{name}.pp.${selinuxvariant} \
%{buildroot}%{_datadir}/selinux/${selinuxvariant}/%{name}.pp
done
popd
make DESTDIR=%{buildroot} install
# avoid to conflict with native postgresql package
mv %{buildroot}%{_bindir} %{buildroot}%{_bindir}.orig
install -d %{buildroot}%{_bindir}
mv %{buildroot}%{_bindir}.orig/initdb %{buildroot}%{_bindir}/initdb.sepgsql
mv %{buildroot}%{_bindir}.orig/pg_ctl %{buildroot}%{_bindir}/sepg_ctl
mv %{buildroot}%{_bindir}.orig/postgres %{buildroot}%{_bindir}/sepostgres
mv %{buildroot}%{_bindir}.orig/pg_dump %{buildroot}%{_bindir}/sepg_dump
mv %{buildroot}%{_bindir}.orig/pg_dumpall %{buildroot}%{_bindir}/sepg_dumpall
# remove unnecessary files
rm -rf %{buildroot}%{_bindir}.orig
rm -rf %{buildroot}%{_libdir}
rm -rf %{buildroot}%{_includedir}
rm -rf %{buildroot}%{_usr}/doc
rm -rf %{buildroot}%{_datadir}/sepgsql/timezone
rm -rf %{buildroot}%{_mandir}
# /var/lib/sepgsql
install -d -m 700 %{buildroot}%{_localstatedir}/lib/sepgsql
install -d -m 700 %{buildroot}%{_localstatedir}/lib/sepgsql/data
install -d -m 700 %{buildroot}%{_localstatedir}/lib/sepgsql/backups
# /etc/rc.d/init.d/*
mkdir -p %{buildroot}%{_initrddir}
install -p -m 755 %{SOURCE1} %{buildroot}%{_initrddir}/sepostgresql
# /etc/logrotate.d/
mkdir -p %{buildroot}%{_sysconfdir}/logrotate.d
install -p -m 644 %{SOURCE6} %{buildroot}%{_sysconfdir}/logrotate.d/sepostgresql
# /usr/share/man/*
mkdir -p %{buildroot}%{_mandir}/man8
install -p -m 644 %{SOURCE5} %{buildroot}%{_mandir}/man8
%clean
rm -rf %{buildroot}
%pre
getent group sepgsql >/dev/null || groupadd -r sepgsql
getent passwd sepgsql >/dev/null || \
useradd -r -g sepgsql -d %{_localstatedir}/lib/sepgsql -s /bin/bash \
-c "SE-PostgreSQL server" sepgsql
exit 0
%post
/sbin/chkconfig --add %{name}
/sbin/ldconfig
for selinuxvariant in %{selinux_variants}
do
%{_sbindir}/semodule -s ${selinuxvariant} -l >& /dev/null || continue;
%{_sbindir}/semodule -s ${selinuxvariant} -l | egrep -q '^%{name}' && \
%{_sbindir}/semodule -s ${selinuxvariant} -r %{name} >& /dev/null || :
%{_sbindir}/semodule -s ${selinuxvariant} -i %{_datadir}/selinux/${selinuxvariant}/%{name}.pp >& /dev/null || :
done
# Fix up non-standard file contexts
/sbin/fixfiles -R %{name} restore || :
/sbin/restorecon -R %{_localstatedir}/lib/sepgsql || :
%preun
if [ $1 -eq 0 ]; then # rpm -e case
/sbin/service %{name} condstop >/dev/null 2>&1
/sbin/chkconfig --del %{name}
fi
%postun
/sbin/ldconfig
if [ $1 -ge 1 ]; then # rpm -U case
/sbin/service %{name} condrestart >/dev/null 2>&1 || :
fi
if [ $1 -eq 0 ]; then # rpm -e case
for selinuxvariant in %{selinux_variants}
do
%{_sbindir}/semodule -s ${selinuxvariant} -l >& /dev/null || continue;
%{_sbindir}/semodule -s ${selinuxvariant} -l | egrep -q '^%{name}' && \
%{_sbindir}/semodule -s ${selinuxvariant} -r %{name} >& /dev/null || :
done
/sbin/fixfiles -R %{name} restore || :
test -d %{_localstatedir}/lib/sepgsql && /sbin/restorecon -R %{_localstatedir}/lib/sepgsql || :
fi
%files
%defattr(-,root,root,-)
%doc COPYRIGHT README HISTORY
%{_initrddir}/sepostgresql
%{_sysconfdir}/logrotate.d/sepostgresql
%{_bindir}/initdb.sepgsql
%{_bindir}/sepg_ctl
%{_bindir}/sepostgres
%{_bindir}/sepg_dump
%{_bindir}/sepg_dumpall
%{_mandir}/man8/sepostgresql.*
%dir %{_datadir}/sepgsql
%{_datadir}/sepgsql/postgres.bki
%{_datadir}/sepgsql/postgres.description
%{_datadir}/sepgsql/postgres.shdescription
%{_datadir}/sepgsql/system_views.sql
%{_datadir}/sepgsql/*.sample
%{_datadir}/sepgsql/snowball_create.sql
%{_datadir}/sepgsql/timezonesets/
%{_datadir}/sepgsql/tsearch_data/
%{_datadir}/sepgsql/conversion_create.sql
%{_datadir}/sepgsql/information_schema.sql
%{_datadir}/sepgsql/sql_features.txt
%attr(644,root,root) %{_datadir}/selinux/*/sepostgresql.pp
%attr(700,sepgsql,sepgsql) %dir %{_localstatedir}/lib/sepgsql
%attr(700,sepgsql,sepgsql) %dir %{_localstatedir}/lib/sepgsql/data
%attr(700,sepgsql,sepgsql) %dir %{_localstatedir}/lib/sepgsql/backups
%changelog
* Sun Mar 9 2008 <kaigai@kaigai.gr.jp> - sepostgresql-8.3.0-2.129
- BUGFIX: more conprehensive fixes in "SELECT COUNT(*) ..."
* Sun Mar 2 2008 <kaigai@kaigai.gr.jp> - sepostgresql-8.3.0-2.120
- BUGFIX: CREATE TABLE statement with explicit labeled columns
- BUGFIX: SELECT count(*) does not filter unallowed tuples
* Wed Feb 27 2008 <kaigai@kaigai.gr.jp> - sepostgresql-8.3.0-2.117
- ".beta" removed.
* Wed Feb 27 2008 <kaigai@kaigai.gr.jp> - sepostgresql-8.3.0-2.114
- Security policy updates
* Tue Feb 26 2008 <kaigai@kaigai.gr.jp> - sepostgresql-8.3.0-2.113
- BUGFIX: CREATE/ALTER TABLE with CONTEXT='...' did nothing.
* Thu Feb 7 2008 <kaigai@kaigai.gr.jp> - sepostgresql-8.3.0-2.108
- add /etc/logrotate.d/sepostgresql
* Thu Feb 7 2008 <kaigai@kaigai.gr.jp> - sepostgresql-8.3.0-2.105
- update base version to stable 8.3.0
- add tzdata dependency
- allow db_database:{get_param set_param} for generic domain
- error message cleanups
- Improve large object hooks in PGACE framework
- BUGFIX: db_blob:{drop} was checked at loread()
- BUGFIX: incorrect permission in DELETE with RETURNING clause
- incorrect permission when we read and update security_context in same time.
* Fri Jan 25 2008 <kaigai@kaigai.gr.jp> - sepostgresql-8.3RC2-2.62
- BUGFIX: add handling to invalid contexts already stored
* Tue Jan 22 2008 <kaigai@kaigai.gr.jp> - sepostgresql-8.3RC2-2.56
- BUGFIX: lack of locks when refering buffer pages at update/delete hooks
- BUGFIX: explicit labeling using SELECT ... INTO statement.
* Sun Jan 20 2008 <kaigai@kaigai.gr.jp> - sepostgresql-8.3RC2-2.52
- shares /usr/lib/pgsql/*.so libraries, with original postgresql.
* Thu Jan 10 2008 <kaigai@kaigai.gr.jp> - sepostgresql-8.3RC1-2.37
- add sepg_dump/sepg_dumpall support for 8.3base package.
* Mon Nov 26 2007 <kaigai@kaigai.gr.jp> - 8.3beta3-2.0
- Branch from 8.2.x tree
* Wed Nov 21 2007 <kaigai@kaigai.gr.jp> - 8.2.5-1.66
- Add a policy module hotfix for labeled networking
* Thu Nov 1 2007 <kaigai@kaigai.gr.jp> - 8.2.5-1.51
- Re-organize repository to prepare to branch 8.3.x based tree.
(no differences from 8.2.5-1.33)
* Wed Oct 17 2007 <kaigai@kaigai.gr.jp> - 8.2.5-1.33
- Fix bug: security context was not canonicalized
when irregular context (but interpretable) was inputed.
* Mon Oct 15 2007 <kaigai@kaigai.gr.jp> - 8.2.5-1.31
- Fix bug: type definitions of security_label_to_text()
and text_to_security_label() are mismatched.
* Sat Sep 22 2007 <kaigai@kaigai.gr.jp> - 8.2.5-1.23
- update base PostgreSQL to 8.2.5
* Mon Sep 1 2007 <kaigai@kaigai.gr.jp> - 8.2.4-1.0
- mark as SE-PostgreSQL 8.2.4-1.0
* Thu Aug 28 2007 <kaigai@kaigai.gr.jp> - 8.2.4-0.434.beta
- add Requires: postgresql-server, instead of Conflicts: tag
(Some sharable files are removed from sepostgresql package)
* Fri Aug 24 2007 <kaigai@kaigai.gr.jp> - 8.2.4-0.429.beta
- add policycoreutils to Requires(post/postun)
- upstreamed selinux-policy got SE-PostgreSQL related object classes definition.
* Sat Aug 18 2007 <kaigai@kaigai.gr.jp> - 8.2.4-0.427.beta
- sepg_dumpall uses /usr/bin/sepg_dump
* Fri Aug 17 2007 <kaigai@kaigai.gr.jp> - 8.2.4-0.423.beta
- fix policy not to execute sepgsql_user_proc_t from administrative domain
* Fri Aug 10 2007 <kaigai@kaigai.gr.jp> - 8.2.4-0.418.beta
- object classes are renamed with "db_" prefix
- /etc/init.d/sepostgresql script is improved.
* Thu Aug 2 2007 <kaigai@kaigai.gr.jp> - 8.2.4-0.409.beta
- specfile updated based on the following comments
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=249522#c5
* Mon Jul 30 2007 <kaigai@kaigai.gr.jp> - 8.2.4-0.407.beta
- fix spec file based on Fedora reviewing process
- add rawhide support
* Mon Jul 23 2007 <kaigai@kaigai.gr.jp> - 8.2.4-0.402.beta
- add manpage of sepostgresql
- fix specfile convention for Fedora suitable
* Sun Jul 15 2007 <kaigai@kaigai.gr.jp> - 8.2.4-0.398.beta
- SECCLASS_DATABASE is updated (fc7->62, fc6->61)
* Sun Jul 1 2007 <kaigai@kaigai.gr.jp> - 8.2.4-0.391.beta
- Mark as a beta version.
* Sat Jun 30 2007 <kaigai@kaigai.gr.jp> - 8.2.4-0.384.alpha
- add fallback context support with $SEPGSQL_FALLBACK_CONTEXT
- add sepgsql_enable_users_ddl boolean to restrict sepgsql_sysobj_t
- BUGFIX: incorrect inherited attribute expanding for RECORD type (attno=0)
- BUGFIX: trigger functions were not checked in COPY FROM statement
* Tue Jun 26 2007 <kaigai@kaigai.gr.jp> - 8.2.4-0.376.alpha
- add pgaceExecutorStart() to hook ExecutorStart()
* Mon Jun 25 2007 <kaigai@kaigai.gr.jp> - 8.2.4-0.372.alpha
- add table name prefix for column name on audit messages
- use security_label_raw_in as an alternative for security_label_in
- add hook for query execution path with SPI_ interface
- add trigger function suppoer
- BUGFIX: remove unnecessary checks for COPY TO/FROM on non-table relation
- BUGFIX: remove unnecessary checks for LOCK on non-table relation
- BUGFIX: incorrect object id for tuples within pg_security
- BUGFIX: CommandCounterIncrement() might be called during heap_create_with_catalog.
- BUGFIX: correct self-deadlock
- update security policy: sepgsql_sysobj_t, sepgsql_user_proc_t, sepgsql_ro_blob_t
* Tue Jun 19 2007 <kaigai@kaigai.gr.jp> - 8.2.4-0.351.alpha
- BUGFIX: sepgsql_compute_avc_datum() accessed userspace AVC without
holding any lock.
- improve build scripts.
* Sat Jun 16 2007 <kaigai@kaigai.gr.jp> - 8.2.4-0.320.alpha
- update: sepostgresql.pp security policy fot strict/mls suitable
- BUGFIX: column:drop evaluation for ALTER TABLE tbl DROP col; statement
- add --enable-security option for pg_dumpall command
- add {use} permission for table/column/tuple object classes
* Tue May 29 2007 <kaigai@kaigai.gr.jp> - 8.2.4-0.306.alpha
- BUGFIX: RangeTblEntry->requiredPerms are polluted.
* Sun May 27 2007 <kaigai@kaigai.gr.jp> - 8.2.4-0.304.alpha
- add support for dynamic object class/access vector mapping
- BUGFIX: Lack of implicit labeling on COPY FROM statement for system catalogs
- BUGFIX: Incorrect security context handling for inherited tables
* Fri May 25 2007 <kaigai@kaigai.gr.jp> - 8.2.4-0.292.alpha
- add pg_dump/pg_dumpall/pg_restore with --enable-security option
- add support on OUTER JOIN by rewriting query.
- add security_context support on COPY TO/FROM statement
- add unlabeled security context support (enable to obtain /selinux/initial_contexts/*)
- BUGFIX: lack of checks on JOIN ON condition
- BUGFIX: pseudo relation object (sequence, toast, ...) are not handled as database obj.
- BUGFIX: lack of tuple:insert checks at COPY FROM statement
- BUGFIX: server crash when CREATE TABLE command with newly defined CONTEXT = '...'.
* Wed May 16 2007 <kaigai@kaigai.gr.jp> - 8.2.4-0.266.alpha
- BUGFIX: incorrect security context of newly generated system object.
- BUGFIX: missing error text when audit log is disabled.
- BUGFIX: incorrect Oid of newly generated tuples within pg_security.
- BUGFIX: sepgsql_enable_audittuple is misconditioned.
- add checks for T_RowExpr/T_RowCompareExpr/T_BooleanTest
T_DistinctExpr/T_ConvertRowtypeExpr
- add support CONTEXT = 'xxx' for CREATE TABLE/FUNCTION/DATABASE statement
* Sun Apr 30 2007 <kaigai@kaigai.gr.jp> - 8.2.4-0.240.alpha
- update base version 8.2.3 -> 8.2.4
- BUGFIX: unexpected expose in OUTER JOIN statement.
add rewrite OUTER JOIN into SUBQUERY to ensure filtering violated tuples.
- BUGFIX: strange operation in text_to_security_label()
- BUGFIX: infinite recursive call on security label -> oid mapping
- BUGFIX: sepgsql_avc_init() is called in policy state monitoring process
to avoid nonsense initialization of avc_shmem.
* Fri Apr 27 2007 <kaigai@kaigai.gr.jp> - 8.2.3-0.232.alpha
- object class numbers were redefined. (SECCLASS_DATABASE got into 61)
- is_selinux_enabled() was cached on the shared memory segment.
- BUGFIX: server went into infinit loop on foreign key constraint.
* Mon Apr 16 2007 <kaigai@kaigai.gr.jp> - 8.2.3-0.226.alpha
- BUGFIX: cases when several variables with same type in a single table
* Sat Apr 07 2007 <kaigai@kaigai.gr.jp> - 8.2.3-0.214.alpha
- add the first implementation of SE-PostgreSQL on PGACE framework
* Wed Mar 21 2007 <kaigai@kaigai.gr.jp> - 8.2.3-0.212.alpha
- BUGFIX: SetOperation didn't handle its subquery correctly.
So, it caused server crash.
* Wed Mar 07 2007 <kaigai@kaigai.gr.jp> - 8.2.3-0.209.alpha
- BUGFIX: var->varlevelsup was ignored, so outer references
from subqueries cause a fault.
* Tue Feb 27 2007 <kaigai@kaigai.gr.jp> - 8.2.3-0.178.alpha
- Initial RPM build

View file

@ -1,353 +0,0 @@
policy_module(sepostgresql, 2.179)
gen_require(`
class db_database all_db_database_perms;
class db_table all_db_table_perms;
class db_procedure all_db_procedure_perms;
class db_column all_db_column_perms;
class db_tuple all_db_tuple_perms;
class db_blob all_db_blob_perms;
type postgresql_t, unlabeled_t;
attribute domain, file_type;
role system_r;
')
#################################
#
# SE-PostgreSQL Boolean declarations
#
## <desc>
## <p>
## Allow to enable unconfined domains
## </p>
## </desc>
gen_tunable(sepgsql_enable_unconfined, true)
## <desc>
## <p>
## Allow to generate auditallow logs
## </p>
## </desc>
gen_tunable(sepgsql_enable_auditallow, false)
## <desc>
## <p>
## Allow to generate auditdeny logs
## </p>
## </desc>
gen_tunable(sepgsql_enable_auditdeny, true)
## <desc>
## <p>
## Allow to generate audit(allow|deny) logs for tuples
## </p>
## </desc>
gen_tunable(sepgsql_enable_audittuple, false)
## <desc>
## <p>
## Allow unprivileged users to execute DDL statement
## </p>
## </desc>
gen_tunable(sepgsql_enable_users_ddl, true)
#################################
#
# SE-PostgreSQL Type/Attribute declarations
#
# database subjects
attribute sepgsql_server_type;
attribute sepgsql_client_type;
attribute sepgsql_unconfined_type;
# database objects attribute
attribute sepgsql_database_type;
attribute sepgsql_table_type;
attribute sepgsql_procedure_type;
attribute sepgsql_blob_type;
attribute sepgsql_module_type;
# database trusted domain
type sepgsql_trusted_domain_t;
# database object types
type sepgsql_db_t, sepgsql_database_type;
type sepgsql_table_t, sepgsql_table_type;
type sepgsql_sysobj_t, sepgsql_table_type;
type sepgsql_secret_table_t, sepgsql_table_type;
type sepgsql_ro_table_t, sepgsql_table_type;
type sepgsql_fixed_table_t, sepgsql_table_type;
type sepgsql_proc_t, sepgsql_procedure_type;
type sepgsql_user_proc_t, sepgsql_procedure_type;
type sepgsql_trusted_proc_t, sepgsql_procedure_type;
type sepgsql_blob_t, sepgsql_blob_type;
type sepgsql_ro_blob_t, sepgsql_blob_type;
type sepgsql_secret_blob_t, sepgsql_blob_type;
typeattribute unlabeled_t sepgsql_database_type;
typeattribute unlabeled_t sepgsql_table_type;
typeattribute unlabeled_t sepgsql_procedure_type;
typeattribute unlabeled_t sepgsql_blob_type;
########################################
#
# SE-PostgreSQL Server Local policy
# (sepgsql_server_type)
allow sepgsql_server_type self : netlink_selinux_socket create_socket_perms;
selinux_get_fs_mount(sepgsql_server_type)
selinux_get_enforce_mode(sepgsql_server_type)
selinux_validate_context(sepgsql_server_type)
selinux_compute_access_vector(sepgsql_server_type)
selinux_compute_create_context(sepgsql_server_type)
selinux_compute_relabel_context(sepgsql_server_type)
allow sepgsql_server_type sepgsql_database_type : db_database *;
allow sepgsql_server_type sepgsql_module_type : db_database { install_module };
allow sepgsql_server_type sepgsql_table_type : { db_table db_column db_tuple } *;
allow sepgsql_server_type sepgsql_procedure_type : db_procedure *;
allow sepgsql_server_type sepgsql_blob_type : db_blob *;
# server specific type transitions
type_transition sepgsql_server_type sepgsql_database_type : db_table sepgsql_sysobj_t;
type_transition sepgsql_server_type sepgsql_database_type : db_procedure sepgsql_proc_t;
########################################
#
# SE-PostgreSQL Administrative domain local policy
# (sepgsql_unconfined_type)
tunable_policy(`sepgsql_enable_unconfined',`
allow sepgsql_unconfined_type sepgsql_database_type : db_database *;
allow sepgsql_unconfined_type sepgsql_module_type : db_database { install_module };
allow sepgsql_unconfined_type sepgsql_table_type : { db_table db_column db_tuple } *;
allow sepgsql_unconfined_type { sepgsql_procedure_type - sepgsql_user_proc_t } : db_procedure *;
allow sepgsql_unconfined_type sepgsql_user_proc_t : db_procedure { create drop getattr setattr relabelfrom relabelto };
allow sepgsql_unconfined_type sepgsql_blob_type : db_blob *;
allow sepgsql_unconfined_type postgresql_t : db_blob { import export };
type_transition { sepgsql_unconfined_type - sepgsql_server_type } sepgsql_database_type : db_procedure sepgsql_proc_t;
',`
type_transition { sepgsql_unconfined_type - sepgsql_server_type } sepgsql_database_type : db_procedure sepgsql_user_proc_t;
')
########################################
#
# SE-PostgreSQL Users domain local policy
# (sepgsql_client_type)
allow sepgsql_client_type sepgsql_db_t : db_database { getattr access get_param set_param};
allow sepgsql_client_type sepgsql_table_t : db_table { getattr use select update insert delete };
allow sepgsql_client_type sepgsql_table_t : db_column { getattr use select update insert };
allow sepgsql_client_type sepgsql_table_t : db_tuple { use select update insert delete };
allow sepgsql_client_type sepgsql_sysobj_t : db_table { getattr use select };
allow sepgsql_client_type sepgsql_sysobj_t : db_column { getattr use select };
allow sepgsql_client_type sepgsql_sysobj_t : db_tuple { use select };
tunable_policy(`sepgsql_enable_users_ddl',`
allow sepgsql_client_type sepgsql_table_t : db_table { create drop setattr };
allow sepgsql_client_type sepgsql_table_t : db_column { create drop setattr };
allow sepgsql_client_type sepgsql_sysobj_t : db_tuple { update insert delete };
')
allow sepgsql_client_type sepgsql_secret_table_t : db_table { getattr };
allow sepgsql_client_type sepgsql_secret_table_t : db_column { getattr };
allow sepgsql_client_type sepgsql_ro_table_t : db_table { getattr use select };
allow sepgsql_client_type sepgsql_ro_table_t : db_column { getattr use select };
allow sepgsql_client_type sepgsql_ro_table_t : db_tuple { use select };
allow sepgsql_client_type sepgsql_fixed_table_t : db_table { getattr use select insert };
allow sepgsql_client_type sepgsql_fixed_table_t : db_column { getattr use select insert };
allow sepgsql_client_type sepgsql_fixed_table_t : db_tuple { use select insert };
allow sepgsql_client_type sepgsql_proc_t : db_procedure { getattr execute };
allow { sepgsql_client_type - sepgsql_unconfined_type } sepgsql_user_proc_t : db_procedure { create drop getattr setattr execute };
allow sepgsql_client_type sepgsql_trusted_proc_t : db_procedure { getattr execute entrypoint };
allow sepgsql_client_type sepgsql_blob_t : db_blob { create drop getattr setattr read write };
allow sepgsql_client_type sepgsql_ro_blob_t : db_blob { getattr read };
allow sepgsql_client_type sepgsql_secret_blob_t : db_blob { getattr };
# call trusted procedure
type_transition sepgsql_client_type sepgsql_trusted_proc_t : process sepgsql_trusted_domain_t;
allow sepgsql_client_type sepgsql_trusted_domain_t : process { transition };
# type transitions for rest of domains
type_transition domain domain : db_database sepgsql_db_t;
type_transition { domain - sepgsql_server_type } sepgsql_database_type : db_table sepgsql_table_t;
type_transition { domain - sepgsql_server_type - sepgsql_unconfined_type } sepgsql_database_type : db_procedure sepgsql_user_proc_t;
type_transition domain sepgsql_database_type : db_blob sepgsql_blob_t;
########################################
#
# SE-PostgreSQL Misc policies
#
# Trusted Procedure Domain
domain_type(sepgsql_trusted_domain_t)
role system_r types sepgsql_trusted_domain_t;
sepgsql_unconfined_domain(sepgsql_trusted_domain_t)
# The following permissions are allowed, even if sepgsql_enable_unconfined is disabled.
allow sepgsql_trusted_domain_t sepgsql_database_type : db_database { getattr setattr access get_param set_param};
allow sepgsql_trusted_domain_t sepgsql_table_type : db_table { getattr use select update insert delete lock };
allow sepgsql_trusted_domain_t sepgsql_table_type : db_column { getattr use select update insert };
allow sepgsql_trusted_domain_t sepgsql_table_type : db_tuple { use select update insert delete };
allow sepgsql_trusted_domain_t { sepgsql_procedure_type - sepgsql_user_proc_t } : db_procedure { getattr execute };
allow sepgsql_trusted_domain_t sepgsql_user_proc_t : db_procedure { getattr };
allow sepgsql_trusted_domain_t sepgsql_blob_type : db_blob { getattr setattr read write };
# Database/Loadable module
allow sepgsql_database_type sepgsql_module_type : db_database { load_module };
########################################
#
# SE-PostgreSQL audit switch
#
tunable_policy(`sepgsql_enable_auditallow',`
auditallow domain sepgsql_database_type : db_database all_db_database_perms;
auditallow domain sepgsql_table_type : db_table all_db_table_perms;
auditallow domain sepgsql_table_type : db_column all_db_column_perms;
auditallow domain sepgsql_procedure_type : db_procedure all_db_procedure_perms;
auditallow domain sepgsql_blob_type : db_blob all_db_blob_perms;
auditallow domain sepgsql_server_type : db_blob { import export };
auditallow domain sepgsql_module_type : db_database { install_module };
')
tunable_policy(`sepgsql_enable_audittuple && sepgsql_enable_auditallow',`
auditallow domain sepgsql_table_type : db_tuple all_db_tuple_perms;
')
tunable_policy(`! sepgsql_enable_auditdeny',`
dontaudit domain sepgsql_database_type : db_database all_db_database_perms;
dontaudit domain sepgsql_table_type : db_table all_db_table_perms;
dontaudit domain sepgsql_table_type : db_column all_db_column_perms;
dontaudit domain sepgsql_procedure_type : db_procedure all_db_procedure_perms;
dontaudit domain sepgsql_blob_type : db_blob all_db_blob_perms;
dontaudit domain sepgsql_server_type : db_blob { import export };
dontaudit domain sepgsql_module_type : db_database { install_module };
')
tunable_policy(`! sepgsql_enable_audittuple || ! sepgsql_enable_auditdeny',`
dontaudit domain sepgsql_table_type : db_tuple all_db_tuple_perms;
')
########################################
#
# Allow permission to external domains
#
# server domains
optional_policy(`
gen_require(`
type postgresql_t;
')
sepgsql_server_domain(postgresql_t)
')
# unconfined client domain
optional_policy(`
gen_require(`
type unconfined_t;
')
sepgsql_unconfined_domain(unconfined_t)
')
optional_policy(`
gen_require(`
type sysadm_t;
')
sepgsql_unconfined_domain(sysadm_t)
')
# generic client domain
optional_policy(`
gen_require(`
type user_t;
role user_r;
')
sepgsql_client_domain(user_t)
sepgsql_trusted_procedure_role(user_r)
')
optional_policy(`
gen_require(`
type staff_t;
role staff_r;
')
sepgsql_client_domain(staff_t)
sepgsql_trusted_procedure_role(staff_r)
')
optional_policy(`
gen_require(`
type user_t;
role user_r;
')
sepgsql_client_domain(user_t)
sepgsql_trusted_procedure_role(user_r)
')
optional_policy(`
gen_require(`
type guest_t;
role guest_r;
')
sepgsql_client_domain(guest_t)
sepgsql_trusted_procedure_role(guest_r)
')
optional_policy(`
gen_require(`
type xguest_t;
role xguest_r;
')
sepgsql_client_domain(xguest_t)
sepgsql_trusted_procedure_role(xguest_r)
')
optional_policy(`
gen_require(`
type httpd_sys_script_t;
')
sepgsql_client_domain(httpd_sys_script_t)
')
# RBAC
optional_policy(`
gen_require(`
role unconfined_r;
')
sepgsql_trusted_procedure_role(unconfined_r)
')
# loadable module types
optional_policy(`
gen_require(`
type lib_t;
')
sepgsql_loadable_module(lib_t)
')
optional_policy(`
gen_require(`
type textrel_shlib_t;
')
sepgsql_loadable_module(textrel_shlib_t)
')
########################################
#
# Hotfixes for labeled networking
#
# NOTE: These changes are to be merged in the later releases.
corenet_tcp_recvfrom_labeled(sepgsql_server_type, sepgsql_client_type)
optional_policy(`
ipsec_match_default_spd(sepgsql_server_type)
ipsec_match_default_spd(sepgsql_client_type)
')

View file

@ -1 +0,0 @@
a5e0ed6a85b450dc217ec71da93243a7 postgresql-8.3.1.tar.bz2