Compare commits
1 commit
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
451b79acc6 |
9 changed files with 1 additions and 20415 deletions
4
.gitignore
vendored
4
.gitignore
vendored
|
|
@ -1,4 +0,0 @@
|
||||||
postgresql-9.0beta1.tar.gz
|
|
||||||
/postgresql-9.0.0.tar.gz
|
|
||||||
/postgresql-9.0.1.tar.gz
|
|
||||||
/postgresql-9.0.3.tar.gz
|
|
||||||
1
dead.package
Normal file
1
dead.package
Normal file
|
|
@ -0,0 +1 @@
|
||||||
|
SE-PostgreSQL was merged into mainstream as contrib/sepgsql extension
|
||||||
File diff suppressed because it is too large
Load diff
|
|
@ -1,105 +0,0 @@
|
||||||
diff --git a/src/Makefile.global.in b/src/Makefile.global.in
|
|
||||||
index 0e3bed5..aee6064 100644
|
|
||||||
--- a/src/Makefile.global.in
|
|
||||||
+++ b/src/Makefile.global.in
|
|
||||||
@@ -74,14 +74,14 @@ bindir := @bindir@
|
|
||||||
datadir := @datadir@
|
|
||||||
ifeq "$(findstring pgsql, $(datadir))" ""
|
|
||||||
ifeq "$(findstring postgres, $(datadir))" ""
|
|
||||||
-override datadir := $(datadir)/postgresql
|
|
||||||
+override datadir := $(datadir)/sepgsql
|
|
||||||
endif
|
|
||||||
endif
|
|
||||||
|
|
||||||
sysconfdir := @sysconfdir@
|
|
||||||
ifeq "$(findstring pgsql, $(sysconfdir))" ""
|
|
||||||
ifeq "$(findstring postgres, $(sysconfdir))" ""
|
|
||||||
-override sysconfdir := $(sysconfdir)/postgresql
|
|
||||||
+override sysconfdir := $(sysconfdir)/sepgsql
|
|
||||||
endif
|
|
||||||
endif
|
|
||||||
|
|
||||||
@@ -90,7 +90,7 @@ libdir := @libdir@
|
|
||||||
pkglibdir = $(libdir)
|
|
||||||
ifeq "$(findstring pgsql, $(pkglibdir))" ""
|
|
||||||
ifeq "$(findstring postgres, $(pkglibdir))" ""
|
|
||||||
-override pkglibdir := $(pkglibdir)/postgresql
|
|
||||||
+override pkglibdir := $(pkglibdir)/sepgsql
|
|
||||||
endif
|
|
||||||
endif
|
|
||||||
|
|
||||||
@@ -99,7 +99,7 @@ includedir := @includedir@
|
|
||||||
pkgincludedir = $(includedir)
|
|
||||||
ifeq "$(findstring pgsql, $(pkgincludedir))" ""
|
|
||||||
ifeq "$(findstring postgres, $(pkgincludedir))" ""
|
|
||||||
-override pkgincludedir := $(pkgincludedir)/postgresql
|
|
||||||
+override pkgincludedir := $(pkgincludedir)/sepgsql
|
|
||||||
endif
|
|
||||||
endif
|
|
||||||
|
|
||||||
@@ -108,7 +108,7 @@ mandir := @mandir@
|
|
||||||
docdir := @docdir@
|
|
||||||
ifeq "$(findstring pgsql, $(docdir))" ""
|
|
||||||
ifeq "$(findstring postgres, $(docdir))" ""
|
|
||||||
-override docdir := $(docdir)/postgresql
|
|
||||||
+override docdir := $(docdir)/sepgsql
|
|
||||||
endif
|
|
||||||
endif
|
|
||||||
|
|
||||||
diff --git a/src/bin/initdb/initdb.c b/src/bin/initdb/initdb.c
|
|
||||||
index 497bdf0..54908f8 100644
|
|
||||||
--- a/src/bin/initdb/initdb.c
|
|
||||||
+++ b/src/bin/initdb/initdb.c
|
|
||||||
@@ -2722,7 +2722,7 @@ main(int argc, char *argv[])
|
|
||||||
*/
|
|
||||||
putenv("TZ=GMT");
|
|
||||||
|
|
||||||
- if ((ret = find_other_exec(argv[0], "postgres", PG_BACKEND_VERSIONSTR,
|
|
||||||
+ if ((ret = find_other_exec(argv[0], "sepostgres", PG_BACKEND_VERSIONSTR,
|
|
||||||
backend_exec)) < 0)
|
|
||||||
{
|
|
||||||
char full_path[MAXPGPATH];
|
|
||||||
diff --git a/src/bin/pg_ctl/pg_ctl.c b/src/bin/pg_ctl/pg_ctl.c
|
|
||||||
index 814ce97..2550e57 100644
|
|
||||||
--- a/src/bin/pg_ctl/pg_ctl.c
|
|
||||||
+++ b/src/bin/pg_ctl/pg_ctl.c
|
|
||||||
@@ -654,7 +654,7 @@ do_init(void)
|
|
||||||
char cmd[MAXPGPATH];
|
|
||||||
|
|
||||||
if (exec_path == NULL)
|
|
||||||
- exec_path = find_other_exec_or_die(argv0, "initdb", "initdb (PostgreSQL) " PG_VERSION "\n");
|
|
||||||
+ exec_path = find_other_exec_or_die(argv0, "initdb.sepgsql", "initdb (PostgreSQL) " PG_VERSION "\n");
|
|
||||||
|
|
||||||
if (pgdata_opt == NULL)
|
|
||||||
pgdata_opt = "";
|
|
||||||
@@ -699,7 +699,7 @@ do_start(void)
|
|
||||||
pgdata_opt = "";
|
|
||||||
|
|
||||||
if (exec_path == NULL)
|
|
||||||
- exec_path = find_other_exec_or_die(argv0, "postgres", PG_BACKEND_VERSIONSTR);
|
|
||||||
+ exec_path = find_other_exec_or_die(argv0, "sepostgres", PG_BACKEND_VERSIONSTR);
|
|
||||||
|
|
||||||
#if defined(HAVE_GETRLIMIT) && defined(RLIMIT_CORE)
|
|
||||||
if (allow_core_files)
|
|
||||||
@@ -1069,7 +1069,7 @@ pgwin32_CommandLine(bool registration)
|
|
||||||
}
|
|
||||||
else
|
|
||||||
{
|
|
||||||
- ret = find_other_exec(argv0, "postgres", PG_BACKEND_VERSIONSTR,
|
|
||||||
+ ret = find_other_exec(argv0, "sepostgres", PG_BACKEND_VERSIONSTR,
|
|
||||||
cmdLine);
|
|
||||||
if (ret != 0)
|
|
||||||
{
|
|
||||||
diff --git a/src/bin/pg_dump/pg_dumpall.c b/src/bin/pg_dump/pg_dumpall.c
|
|
||||||
index 83f1678..a0a9444 100644
|
|
||||||
--- a/src/bin/pg_dump/pg_dumpall.c
|
|
||||||
+++ b/src/bin/pg_dump/pg_dumpall.c
|
|
||||||
@@ -156,7 +156,7 @@ main(int argc, char *argv[])
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
- if ((ret = find_other_exec(argv[0], "pg_dump", PGDUMP_VERSIONSTR,
|
|
||||||
+ if ((ret = find_other_exec(argv[0], "sepg_dump", PGDUMP_VERSIONSTR,
|
|
||||||
pg_dump_bin)) < 0)
|
|
||||||
{
|
|
||||||
char full_path[MAXPGPATH];
|
|
||||||
137
sepostgresql.8
137
sepostgresql.8
|
|
@ -1,137 +0,0 @@
|
||||||
.TH "sepostgresql" "8" "Jul 15 2007" "kaigai@kaigai.gr.jp" "Security-Enhanced PostgreSQL"
|
|
||||||
|
|
||||||
.SH "NAME"
|
|
||||||
sepostgresql \- Security-Enhances PostgreSQL
|
|
||||||
|
|
||||||
.SH "DESCRIPTION"
|
|
||||||
Security-Enhanced PostgreSQL (SE-PostgreSQL) is an enhancement of PostgreSQL,
|
|
||||||
to apply fine grained mandatory access control for database objects based on
|
|
||||||
the security policy of SELinux.
|
|
||||||
These features enable to apply flexible integrated access control policy
|
|
||||||
on both of operating system and database management system, during all
|
|
||||||
stages of the life of the information.
|
|
||||||
.PP
|
|
||||||
This document describes the way to customize SE-PostgreSQL on the default
|
|
||||||
security policy.
|
|
||||||
|
|
||||||
.SH "BOOLEANS"
|
|
||||||
The SELinux policy is customizable via BOOLEAN variable. This variable has
|
|
||||||
two states, 1 (on) or 0 (off). We can validate or invalidate a part of the
|
|
||||||
security policy depending on the state of boolean variables.
|
|
||||||
|
|
||||||
\fBsepgsql_enable_users_ddl\fP enables to toggle permissions of confined
|
|
||||||
users/applications to invoke DDL statement, like CREATE TABLE. It is set to
|
|
||||||
\fBon\fP in the default.
|
|
||||||
In most cases, DDL statements are used to set up initial database structure,
|
|
||||||
and permissions to invoke them are not necessary on operation phase.
|
|
||||||
You can turn off this boolean as follows:
|
|
||||||
|
|
||||||
.EX
|
|
||||||
setsebool -P sepgsql_enable_users_ddl ( \fBon\fP | off )
|
|
||||||
.EE
|
|
||||||
|
|
||||||
Rest of booleans are provided by \fBselinux-devel.pp\fP policy module.
|
|
||||||
It provides developments/debugs related permissions.
|
|
||||||
You can install it as follows:
|
|
||||||
|
|
||||||
.EX
|
|
||||||
semodule -i /usr/share/selinux/targeted/sepostgresql-devel.pp
|
|
||||||
.EE
|
|
||||||
|
|
||||||
\fBsepgsql_enable_auditallow\fP toggles output of audit messages in the case
|
|
||||||
when required permission checks are allowed, except for tuples because it
|
|
||||||
easily make a flood of audit logs.
|
|
||||||
In the default, it is set to off. You can set it as follows:
|
|
||||||
|
|
||||||
.EX
|
|
||||||
setsebool -P sepgsql_enable_auditallow ( on | \fBoff\fP )
|
|
||||||
.EE
|
|
||||||
|
|
||||||
\fBsepgsql_enable_auditdeny\fP toggles output of audit messages in the case
|
|
||||||
when required permission checks are denied, except for tuples because it
|
|
||||||
easily make a flood of audit logs.
|
|
||||||
In the default, it is set to on. You can set it as follows:
|
|
||||||
|
|
||||||
.EX
|
|
||||||
setsebool -P sepgsql_enable_auditdeny ( \fBon\fP | off )
|
|
||||||
.EE
|
|
||||||
|
|
||||||
\fBsepgsql_regression_test_mode\fP allows to load shared libraries deployed
|
|
||||||
on user's home directory. We recommend you to keep \fBoff\fP in operation
|
|
||||||
phase to prevent to load malicious libraries.
|
|
||||||
However, typical PostgreSQL regression test requires to load it, so we
|
|
||||||
have to reduce several restriction during the test.
|
|
||||||
In the default, it is set to off. You can set it as follows:
|
|
||||||
|
|
||||||
.EX
|
|
||||||
setsebool -P sepgsql_regression_test_mode ( on | \fBoff\fP )
|
|
||||||
.EE
|
|
||||||
|
|
||||||
.SH "TYPES"
|
|
||||||
|
|
||||||
\fBsepgsql_db_t\fP is a only type for database itself.
|
|
||||||
It is attched for newly created databases in the default.
|
|
||||||
|
|
||||||
\fBsepgsql_table_t\fP is a type for tables, columns and tuples.
|
|
||||||
It is the default type of newly created tables by unconfined or
|
|
||||||
non-roled domain. It allows confined clietns to access with any
|
|
||||||
kind of operations except for relabeling, so we can use this type
|
|
||||||
for compatible purpose.
|
|
||||||
|
|
||||||
\fBsepgsql_secret_table_t\fP is a type for tables, columns and tuples.
|
|
||||||
It never allows confined clients to access, so we can use this type
|
|
||||||
to store sensitive information. We reccomend to apply trusted procedures
|
|
||||||
to access tables/columns/tuples with this type under safe operation.
|
|
||||||
|
|
||||||
\fBsepgsql_ro_table_t\fP is a type for read-only tables, columns and tuples.
|
|
||||||
It does not allow confined clients to modify any objects with this type.
|
|
||||||
|
|
||||||
\fBsepgsql_fixed_table_t\fP is a type for non-manupulatable tables, columns
|
|
||||||
and tuples. It does not allow confined clients to update or delete any
|
|
||||||
objects with this type.
|
|
||||||
|
|
||||||
\fBsepgsql_ROLE_table_t\fP is a type for a role specific tables, columns
|
|
||||||
and tuples. It allows confined clients with its role to access with any
|
|
||||||
kind of operations except for relabeling.
|
|
||||||
It is the default type of newly created tables by confined clients with
|
|
||||||
its role, and we can use this type to describe role level separation.
|
|
||||||
|
|
||||||
\fBsepgsql_proc_t\fP is a type for procedures.
|
|
||||||
It is attached for newly created procedures by unconfined clients.
|
|
||||||
It allows any clients to invoke procedures with this type.
|
|
||||||
All of PostgreSQL built-in functions are labeled as this type in the default.
|
|
||||||
|
|
||||||
\fBsepgsql_ROLE_proc_t\fP is a type for a role specific procedure.
|
|
||||||
It is attached for newly created procedures by confined clients with its role.
|
|
||||||
It allows clients with same role to invoke procedure with this type.
|
|
||||||
Note that unconfined clients cannot invoke this type to avoid to execute
|
|
||||||
dangerous functions with unconfined authorities. They have to confirm its
|
|
||||||
contains and relabel to \fBsepgsql_proc_t\fP for its invocation.
|
|
||||||
|
|
||||||
\fBsepgsql_trusted_proc_exec_t\fP is a type for trusted procedures.
|
|
||||||
To call procedures with this type invokes domain transition to
|
|
||||||
unconfined domain, so it can access any kind of database objects.
|
|
||||||
We can use this type to provide a secure method to access sensitive
|
|
||||||
information.
|
|
||||||
|
|
||||||
\fBsepgsql_blob_t\fP is a type for binary large objects (blob).
|
|
||||||
It is attached for newly created blob in the default.
|
|
||||||
Non-administrative clients can read and write the blobs with this type.
|
|
||||||
|
|
||||||
\fBsepgsql_ro_blob_t\fP is a type for read-only binary large objects (blob).
|
|
||||||
Non-administrative clients cannot write the blobs with this type.
|
|
||||||
|
|
||||||
.SH "BACKUP and RESTORE"
|
|
||||||
\fI--enable-selinux\fP option in \fBsepg_dump\fP and \fBsepg_dumpall\fP enable to dump database image with security context. We can restore the dumped image using the standard \fIpg_restore\fP and so on.
|
|
||||||
|
|
||||||
.EX
|
|
||||||
Example)
|
|
||||||
$ sepg_dump -Ft -b --enable-selinux postgres | gzip -c > postgres.tgz
|
|
||||||
.EE
|
|
||||||
|
|
||||||
.SH AUTHOR
|
|
||||||
This manual page was written by KaiGai Kohei <kaigai@kaigai.gr.jp>
|
|
||||||
|
|
||||||
.SH "SEE ALSO"
|
|
||||||
|
|
||||||
selinux(8), boolean(8)
|
|
||||||
|
|
@ -1,205 +0,0 @@
|
||||||
#!/bin/sh
|
|
||||||
# sepostgresql This is the init script for starting up SE-PostgreSQL
|
|
||||||
#
|
|
||||||
# chkconfig: - 62 38
|
|
||||||
# description: Starts and stops the SE-PostgreSQL backend daemon
|
|
||||||
# processname: postmaster
|
|
||||||
# pidfile: /var/run/postmaster.pid
|
|
||||||
#---------------------------------------------------------------------
|
|
||||||
|
|
||||||
# source function library
|
|
||||||
. /etc/rc.d/init.d/functions
|
|
||||||
|
|
||||||
# get config
|
|
||||||
. /etc/sysconfig/network
|
|
||||||
|
|
||||||
# find the name of the script
|
|
||||||
NAME=`basename $0`
|
|
||||||
if [ ${NAME:0:1} = "S" -o ${NAME:0:1} = "K" ]; then
|
|
||||||
NAME=${NAME:3}
|
|
||||||
fi
|
|
||||||
|
|
||||||
PGVERSION=`rpm -q --queryformat='%{version}' ${NAME}`
|
|
||||||
PGMAJORVERSION=`echo "$PGVERSION" | sed 's/^\([0-9]*\.[0-9a-z]*\).*$/\1/'`
|
|
||||||
|
|
||||||
# set defaults for configurable variables
|
|
||||||
SEPGSQL_CTL="/usr/bin/sepg_ctl"
|
|
||||||
SEPGSQL_DATA="/var/lib/sepgsql/data"
|
|
||||||
SEPGSQL_OPTS="-i -p 5432"
|
|
||||||
SEPGSQL_STARTUP_LOG="/var/lib/sepgsql/pgstartup.log"
|
|
||||||
SEPGSQL_LOG="/var/log/sepostgresql.log"
|
|
||||||
|
|
||||||
# override defaults from /etc/sysconfig/sepostgresql
|
|
||||||
test -f /etc/sysconfig/${NAME} && . /etc/sysconfig/${NAME}
|
|
||||||
|
|
||||||
# Check that networking is up.
|
|
||||||
test "${NETWORKING}" = "no" && exit 0
|
|
||||||
test -f "/usr/bin/sepostgres" || exit 1
|
|
||||||
|
|
||||||
script_result=0
|
|
||||||
|
|
||||||
do_start() {
|
|
||||||
PSQL_START=$"Starting ${NAME} service: "
|
|
||||||
echo -n "$PSQL_START"
|
|
||||||
|
|
||||||
# make sure startup-time log file is valid
|
|
||||||
if [ ! -e "${SEPGSQL_STARTUP_LOG}" -a ! -h "${SEPGSQL_STARTUP_LOG}" ]; then
|
|
||||||
touch "${SEPGSQL_STARTUP_LOG}" || exit 1
|
|
||||||
chown sepgsql:sepgsql "${SEPGSQL_STARTUP_LOG}"
|
|
||||||
chmod 600 "${SEPGSQL_STARTUP_LOG}"
|
|
||||||
/sbin/restorecon "${SEPGSQL_STARTUP_LOG}"
|
|
||||||
fi
|
|
||||||
|
|
||||||
# check for the SEPGSQL_DATA structure
|
|
||||||
if [ -f "${SEPGSQL_DATA}/PG_VERSION" ] && [ -d "${SEPGSQL_DATA}/base" ]; then
|
|
||||||
if [ x`cat "${SEPGSQL_DATA}/PG_VERSION"` != x"${PGMAJORVERSION}" ]; then
|
|
||||||
echo_failure
|
|
||||||
echo
|
|
||||||
echo "HINT: An old version of the database format was found."
|
|
||||||
echo "HINT: You need to upgrade the data format before using SE-PostgreSQL."
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
else
|
|
||||||
echo_failure
|
|
||||||
echo
|
|
||||||
echo "HINT: ${SEPGSQL_DATA} is missing."
|
|
||||||
echo "HINT: Use '/etc/init.d/${NAME} initdb'"
|
|
||||||
echo "HINT: to initialize the database cluster first."
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
# make sure SEPGSQL_LOG
|
|
||||||
touch ${SEPGSQL_LOG}
|
|
||||||
chown sepgsql:sepgsql ${SEPGSQL_LOG}
|
|
||||||
chmod 600 ${SEPGSQL_LOG}
|
|
||||||
test -x /sbin/restorecon && /sbin/restorecon ${SEPGSQL_LOG}
|
|
||||||
|
|
||||||
/sbin/runuser sepgsql -c "${SEPGSQL_CTL} -w -t 10 -l ${SEPGSQL_LOG} -D ${SEPGSQL_DATA} -o '${SEPGSQL_OPTS}' start" \
|
|
||||||
>> ${SEPGSQL_STARTUP_LOG} 2>&1 < /dev/null
|
|
||||||
sleep 1
|
|
||||||
PID=`/sbin/runuser sepgsql -c "${SEPGSQL_CTL} -D ${SEPGSQL_DATA} status 2>/dev/null \
|
|
||||||
| sed 's/^.*PID: //g' | sed 's/[^0-9].*$//g'"`
|
|
||||||
if [ ${PIPESTATUS[0]} -eq 0 ]; then
|
|
||||||
echo "$PID" > "/var/run/${NAME}.pid"
|
|
||||||
touch "/var/lock/subsys/${NAME}.lock"
|
|
||||||
echo_success
|
|
||||||
else
|
|
||||||
script_result=1
|
|
||||||
echo_failure
|
|
||||||
fi
|
|
||||||
echo
|
|
||||||
}
|
|
||||||
|
|
||||||
do_stop() {
|
|
||||||
echo -n $"Stopping ${NAME} service: "
|
|
||||||
/sbin/runuser sepgsql -c "${SEPGSQL_CTL} -D ${SEPGSQL_DATA} stop" \
|
|
||||||
>> ${SEPGSQL_STARTUP_LOG} 2>&1 < /dev/null
|
|
||||||
ret=$?
|
|
||||||
if [ $ret -eq 0 ]; then
|
|
||||||
echo_success
|
|
||||||
else
|
|
||||||
echo_failure
|
|
||||||
script_result=1
|
|
||||||
fi
|
|
||||||
echo
|
|
||||||
rm -f "/var/run/${NAME}.pid"
|
|
||||||
rm -f "/var/lock/subsys/${NAME}.lock"
|
|
||||||
}
|
|
||||||
|
|
||||||
do_status() {
|
|
||||||
/sbin/runuser sepgsql -- -c "${SEPGSQL_CTL} -D ${SEPGSQL_DATA} status" 2>/dev/null \
|
|
||||||
| head -1 | sed "s/^sepg_ctl:/${NAME}:/g"
|
|
||||||
|
|
||||||
if [ ${PIPESTATUS[0]} -ne 0 ]; then
|
|
||||||
script_result=3
|
|
||||||
test -e "/var/run/${NAME}.pid" && script_result=1
|
|
||||||
test -e "/var/lock/subsys/${NAME}.lock" && script_result=2
|
|
||||||
fi
|
|
||||||
}
|
|
||||||
|
|
||||||
do_condrestart() {
|
|
||||||
cd ${SEPGSQL_BIN}
|
|
||||||
/sbin/runuser sepgsql -- -c "${SEPGSQL_CTL} -D ${SEPGSQL_DATA} status" &>/dev/null && do_stop && do_start
|
|
||||||
}
|
|
||||||
|
|
||||||
do_condstop() {
|
|
||||||
cd ${SEPGSQL_BIN}
|
|
||||||
/sbin/runuser sepgsql -- -c "${SEPGSQL_CTL} -D ${SEPGSQL_DATA} status" &>/dev/null && do_stop
|
|
||||||
}
|
|
||||||
|
|
||||||
do_reload() {
|
|
||||||
echo -n $"Reloading ${NAME} service: "
|
|
||||||
cd ${SEPGSQL_BIN}
|
|
||||||
/sbin/runuser sepgsql -- -c "${SEPGSQL_CTL} -D ${SEPGSQL_DATA} reload" &>/dev/null < /dev/null
|
|
||||||
if [ $? -eq 0 ]; then
|
|
||||||
echo_success
|
|
||||||
else
|
|
||||||
echo_failure
|
|
||||||
script_result=1
|
|
||||||
fi
|
|
||||||
echo
|
|
||||||
}
|
|
||||||
|
|
||||||
do_initdb() {
|
|
||||||
echo -n $"Initializing database: "
|
|
||||||
|
|
||||||
if [ -f "${SEPGSQL_DATA}/PG_VERSION" ]; then
|
|
||||||
echo_failure
|
|
||||||
echo
|
|
||||||
echo "HINT: Data directory is not empty"
|
|
||||||
script_result=1
|
|
||||||
else
|
|
||||||
if [ ! -e "${SEPGSQL_DATA}" -a ! -h "${SEPGSQL_DATA}" ]; then
|
|
||||||
mkdir -p "${SEPGSQL_DATA}" || exit 1
|
|
||||||
chown sepgsql:sepgsql "${SEPGSQL_DATA}"
|
|
||||||
chmod 600 "${SEPGSQL_DATA}"
|
|
||||||
fi
|
|
||||||
# cleanup SELinux labeling for "${SEPGSQL_DATA}"
|
|
||||||
test -x /sbin/restorecon && /sbin/restorecon -R "${SEPGSQL_DATA}"
|
|
||||||
# Initialize the database
|
|
||||||
/sbin/runuser -- sepgsql -c "${SEPGSQL_CTL} initdb -o '--enable-selinux --pgdata=${SEPGSQL_DATA} --auth=ident' -D ${SEPGSQL_DATA}" \
|
|
||||||
>> "${SEPGSQL_STARTUP_LOG}" 2>&1 < /dev/null
|
|
||||||
if [ -f "${SEPGSQL_DATA}/PG_VERSION" ]; then
|
|
||||||
echo_success
|
|
||||||
else
|
|
||||||
echo_failure
|
|
||||||
script_result=1
|
|
||||||
fi
|
|
||||||
echo
|
|
||||||
fi
|
|
||||||
}
|
|
||||||
|
|
||||||
# see how we were called.
|
|
||||||
case "$1" in
|
|
||||||
start)
|
|
||||||
do_start
|
|
||||||
;;
|
|
||||||
stop)
|
|
||||||
do_stop
|
|
||||||
;;
|
|
||||||
status)
|
|
||||||
do_status
|
|
||||||
;;
|
|
||||||
restart)
|
|
||||||
do_stop
|
|
||||||
do_start
|
|
||||||
;;
|
|
||||||
condrestart)
|
|
||||||
do_condrestart
|
|
||||||
;;
|
|
||||||
condstop)
|
|
||||||
do_condstop
|
|
||||||
;;
|
|
||||||
reload|force-reload)
|
|
||||||
do_reload
|
|
||||||
;;
|
|
||||||
initdb)
|
|
||||||
do_initdb
|
|
||||||
;;
|
|
||||||
*)
|
|
||||||
echo $"Usage: $0 {start|stop|status|restart|condrestart|condstop|reload|force-reload|initdb}"
|
|
||||||
exit 1
|
|
||||||
;;
|
|
||||||
esac
|
|
||||||
|
|
||||||
exit $script_result
|
|
||||||
|
|
@ -1,11 +0,0 @@
|
||||||
# logrotate configuration for SE-PostgreSQL
|
|
||||||
|
|
||||||
/var/log/sepostgresql.log {
|
|
||||||
rotate 4
|
|
||||||
compress
|
|
||||||
size 4M
|
|
||||||
notifempty
|
|
||||||
postrotate
|
|
||||||
/sbin/service sepostgresql restart >& /dev/null
|
|
||||||
endscript
|
|
||||||
}
|
|
||||||
|
|
@ -1,485 +0,0 @@
|
||||||
#
|
|
||||||
# Security Enhanced PostgreSQL (SE-PostgreSQL)
|
|
||||||
#
|
|
||||||
# Copyright 2007 KaiGai Kohei <kaigai@kaigai.gr.jp>
|
|
||||||
# -----------------------------------------------------
|
|
||||||
|
|
||||||
# SE-PostgreSQL status extension
|
|
||||||
%define selinux_policy_stores targeted mls
|
|
||||||
|
|
||||||
%{!?ssl:%define ssl 1}
|
|
||||||
|
|
||||||
Summary: Security Enhanced PostgreSQL
|
|
||||||
Name: sepostgresql
|
|
||||||
Version: 9.0.3
|
|
||||||
Release: 20110416%{?dist}
|
|
||||||
License: PostgreSQL
|
|
||||||
Group: Applications/Databases
|
|
||||||
Url: http://code.google.com/p/sepgsql/
|
|
||||||
Buildroot: %(mktemp -ud %{_tmppath}/%{name}-%{version}-%{release}-XXXXXX)
|
|
||||||
Source0: ftp://ftp.postgresql.org/pub/source/v%{version}/postgresql-%{version}.tar.gz
|
|
||||||
Source1: sepostgresql.init
|
|
||||||
Source2: sepostgresql.8
|
|
||||||
Source3: sepostgresql.logrotate
|
|
||||||
Patch0: sepostgresql-fedora-prefix.patch
|
|
||||||
Patch1: sepostgresql-9.0-fullset.patch
|
|
||||||
BuildRequires: perl glibc-devel bison flex readline-devel zlib-devel >= 1.0.4
|
|
||||||
BuildRequires: checkpolicy libselinux-devel >= 2.0.96 audit-libs-devel
|
|
||||||
BuildRequires: selinux-policy >= 3.6.8
|
|
||||||
%if %{ssl}
|
|
||||||
BuildRequires: openssl-devel
|
|
||||||
%endif
|
|
||||||
Requires(pre): shadow-utils
|
|
||||||
Requires(post): policycoreutils /sbin/chkconfig
|
|
||||||
Requires(preun): /sbin/chkconfig /sbin/service
|
|
||||||
Requires(postun): policycoreutils
|
|
||||||
Requires: policycoreutils >= 2.0.16 libselinux >= 2.0.96
|
|
||||||
Requires: selinux-policy >= 3.6.8
|
|
||||||
Requires: tzdata logrotate
|
|
||||||
|
|
||||||
%description
|
|
||||||
Security Enhanced PostgreSQL is an extension of PostgreSQL
|
|
||||||
based on SELinux security policy, that applies fine grained
|
|
||||||
mandatory access control to many objects within the database,
|
|
||||||
and takes advantage of user authorization integrated within
|
|
||||||
the operating system. SE-PostgreSQL works as a userspace
|
|
||||||
reference monitor to check any SQL query.
|
|
||||||
|
|
||||||
%prep
|
|
||||||
%setup -q -n postgresql-%{version}
|
|
||||||
%patch0 -p1
|
|
||||||
%patch1 -p1
|
|
||||||
|
|
||||||
%build
|
|
||||||
CFLAGS="${CFLAGS:-%optflags}" ; export CFLAGS
|
|
||||||
CXXFLAGS="${CXXFLAGS:-%optflags}" ; export CXXFLAGS
|
|
||||||
|
|
||||||
# build SE-PostgreSQL
|
|
||||||
%configure --disable-rpath \
|
|
||||||
--enable-selinux \
|
|
||||||
%if %{ssl}
|
|
||||||
--with-openssl \
|
|
||||||
%endif
|
|
||||||
--enable-debug \
|
|
||||||
--enable-cassert \
|
|
||||||
--with-system-tzdata=/usr/share/zoneinfo
|
|
||||||
|
|
||||||
# parallel build, if possible
|
|
||||||
rm -f src/Makefile.custom
|
|
||||||
make %{?_smp_mflags}
|
|
||||||
|
|
||||||
%install
|
|
||||||
rm -rf %{buildroot}
|
|
||||||
|
|
||||||
make DESTDIR=%{buildroot} install
|
|
||||||
|
|
||||||
# avoid to conflict with native postgresql package
|
|
||||||
mv %{buildroot}%{_bindir} %{buildroot}%{_bindir}.orig
|
|
||||||
install -d %{buildroot}%{_bindir}/
|
|
||||||
mv %{buildroot}%{_bindir}.orig/initdb %{buildroot}%{_bindir}/initdb.sepgsql
|
|
||||||
mv %{buildroot}%{_bindir}.orig/pg_ctl %{buildroot}%{_bindir}/sepg_ctl
|
|
||||||
mv %{buildroot}%{_bindir}.orig/postgres %{buildroot}%{_bindir}/sepostgres
|
|
||||||
mv %{buildroot}%{_bindir}.orig/pg_dump %{buildroot}%{_bindir}/sepg_dump
|
|
||||||
mv %{buildroot}%{_bindir}.orig/pg_dumpall %{buildroot}%{_bindir}/sepg_dumpall
|
|
||||||
mv %{buildroot}%{_bindir}.orig/pg_restore %{buildroot}%{_bindir}/sepg_restore
|
|
||||||
|
|
||||||
mv %{buildroot}%{_libdir} %{buildroot}%{_libdir}.orig
|
|
||||||
install -d %{buildroot}%{_libdir}/sepgsql
|
|
||||||
mv %{buildroot}%{_libdir}.orig/sepgsql/dict_snowball.so \
|
|
||||||
%{buildroot}%{_libdir}.orig/sepgsql/plpgsql.so \
|
|
||||||
%{buildroot}%{_libdir}.orig/sepgsql/*_and_*.so \
|
|
||||||
%{buildroot}%{_libdir}.orig/sepgsql/euc2004_sjis2004.so \
|
|
||||||
%{buildroot}%{_libdir}.orig/sepgsql/libpqwalreceiver.so \
|
|
||||||
%{buildroot}%{_libdir}/sepgsql
|
|
||||||
|
|
||||||
# remove unnecessary files
|
|
||||||
rm -rf %{buildroot}%{_bindir}.orig
|
|
||||||
rm -rf %{buildroot}%{_libdir}.orig
|
|
||||||
rm -rf %{buildroot}%{_includedir}
|
|
||||||
rm -rf %{buildroot}%{_datadir}/doc
|
|
||||||
rm -rf %{buildroot}%{_datadir}/sepgsql/timezone
|
|
||||||
rm -rf %{buildroot}%{_mandir}
|
|
||||||
|
|
||||||
# /var/lib/sepgsql
|
|
||||||
install -d -m 700 %{buildroot}%{_localstatedir}/lib/sepgsql
|
|
||||||
install -d -m 700 %{buildroot}%{_localstatedir}/lib/sepgsql/data
|
|
||||||
install -d -m 700 %{buildroot}%{_localstatedir}/lib/sepgsql/backups
|
|
||||||
|
|
||||||
# /etc/rc.d/init.d/*
|
|
||||||
mkdir -p %{buildroot}%{_initrddir}
|
|
||||||
install -p -m 755 %{SOURCE1} %{buildroot}%{_initrddir}/sepostgresql
|
|
||||||
|
|
||||||
# /usr/share/man/*
|
|
||||||
mkdir -p %{buildroot}%{_mandir}/man8
|
|
||||||
install -p -m 644 %{SOURCE2} %{buildroot}%{_mandir}/man8
|
|
||||||
|
|
||||||
# /etc/logrotate.d/
|
|
||||||
mkdir -p %{buildroot}%{_sysconfdir}/logrotate.d
|
|
||||||
install -p -m 644 %{SOURCE3} %{buildroot}%{_sysconfdir}/logrotate.d/sepostgresql
|
|
||||||
|
|
||||||
%clean
|
|
||||||
rm -rf %{buildroot}
|
|
||||||
|
|
||||||
%pre
|
|
||||||
getent group sepgsql >/dev/null || groupadd -r sepgsql
|
|
||||||
getent passwd sepgsql >/dev/null || \
|
|
||||||
useradd -r -g sepgsql -s /bin/bash -c "SE-PostgreSQL" sepgsql
|
|
||||||
exit 0
|
|
||||||
|
|
||||||
%post
|
|
||||||
/sbin/chkconfig --add %{name}
|
|
||||||
/sbin/ldconfig
|
|
||||||
|
|
||||||
# Fix up non-standard file contexts
|
|
||||||
/sbin/fixfiles -R %{name} restore || :
|
|
||||||
/sbin/restorecon -R %{_localstatedir}/lib/sepgsql || :
|
|
||||||
|
|
||||||
%preun
|
|
||||||
if [ $1 -eq 0 ]; then # rpm -e case
|
|
||||||
/sbin/service %{name} condstop >/dev/null 2>&1
|
|
||||||
/sbin/chkconfig --del %{name}
|
|
||||||
fi
|
|
||||||
|
|
||||||
%postun
|
|
||||||
/sbin/ldconfig
|
|
||||||
if [ $1 -ge 1 ]; then # rpm -U case
|
|
||||||
/sbin/service %{name} condrestart >/dev/null 2>&1 || :
|
|
||||||
fi
|
|
||||||
if [ $1 -eq 0 ]; then # rpm -e case
|
|
||||||
/sbin/fixfiles -R %{name} restore || :
|
|
||||||
test -d %{_localstatedir}/lib/sepgsql && \
|
|
||||||
/sbin/restorecon -R %{_localstatedir}/lib/sepgsql || :
|
|
||||||
fi
|
|
||||||
|
|
||||||
%files
|
|
||||||
%defattr(-,root,root,-)
|
|
||||||
%doc COPYRIGHT README
|
|
||||||
%{_initrddir}/sepostgresql
|
|
||||||
%{_sysconfdir}/logrotate.d/sepostgresql
|
|
||||||
%{_bindir}/initdb.sepgsql
|
|
||||||
%{_bindir}/sepg_ctl
|
|
||||||
%{_bindir}/sepostgres
|
|
||||||
%{_bindir}/sepg_dump
|
|
||||||
%{_bindir}/sepg_dumpall
|
|
||||||
%{_bindir}/sepg_restore
|
|
||||||
%{_libdir}/sepgsql/*.so
|
|
||||||
%{_mandir}/man8/sepostgresql.*
|
|
||||||
%dir %{_datadir}/sepgsql
|
|
||||||
%{_datadir}/sepgsql/postgres.bki
|
|
||||||
%{_datadir}/sepgsql/postgres.description
|
|
||||||
%{_datadir}/sepgsql/postgres.shdescription
|
|
||||||
%{_datadir}/sepgsql/system_views.sql
|
|
||||||
%{_datadir}/sepgsql/*.sample
|
|
||||||
%{_datadir}/sepgsql/snowball_create.sql
|
|
||||||
%{_datadir}/sepgsql/timezonesets/
|
|
||||||
%{_datadir}/sepgsql/tsearch_data/
|
|
||||||
%{_datadir}/sepgsql/conversion_create.sql
|
|
||||||
%{_datadir}/sepgsql/information_schema.sql
|
|
||||||
%{_datadir}/sepgsql/sql_features.txt
|
|
||||||
%attr(700,sepgsql,sepgsql) %dir %{_localstatedir}/lib/sepgsql
|
|
||||||
%attr(700,sepgsql,sepgsql) %dir %{_localstatedir}/lib/sepgsql/data
|
|
||||||
%attr(700,sepgsql,sepgsql) %dir %{_localstatedir}/lib/sepgsql/backups
|
|
||||||
|
|
||||||
%changelog
|
|
||||||
* Sat Jan 14 2012 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 9.0.3-20110416
|
|
||||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild
|
|
||||||
|
|
||||||
* Fri Apr 15 2011 KaiGai Kohei <kaigai@kaigai.gr.jp> - 9.0.3-20110415
|
|
||||||
- upgrade base version to 9.0.3
|
|
||||||
- initial labeling logic was revised to use selabel_lookup()
|
|
||||||
|
|
||||||
* Wed Feb 09 2011 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 9.0.1-20101008
|
|
||||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
|
|
||||||
|
|
||||||
* Thu Oct 7 2010 KaiGai Kohei <kaigai@kaigai.gr.jp> - 9.0.1-20101007
|
|
||||||
- upgrade base version to 9.0.1
|
|
||||||
|
|
||||||
* Tue Oct 5 2010 KaiGai Kohei <kaigai@kaigai.gr.jp> - 9.0.0-20101005
|
|
||||||
- upgrade base version to 9.0.0
|
|
||||||
|
|
||||||
* Tue May 11 2010 KaiGai Kohei <kaigai@kaigai.gr.jp> - 9.0.0-20100511
|
|
||||||
- upgrade base version to 9.0beta1
|
|
||||||
|
|
||||||
* Sun Apr 4 2010 KaiGai Kohei <kaigai@kaigai.gr.jp> - 9.0.0-20100404
|
|
||||||
- upgrade base version 8.4.3->9.0alpha5
|
|
||||||
|
|
||||||
* Thu Mar 18 2010 KaiGai Kohei <kaigai@ak.jp.nec.com> - 8.4.3-2582
|
|
||||||
- upgrade base version 8.4.2->8.4.3
|
|
||||||
|
|
||||||
* Mon Feb 15 2010 KaiGai Kohei <kaigai@ak.jp.nec.com> - 8.4.2-2488
|
|
||||||
- fix: build failed due to an implicit header file include
|
|
||||||
- update: feature backport from v8.5 development
|
|
||||||
|
|
||||||
* Wed Dec 16 2009 KaiGai Kohei <kaigai@kaigai.gr.jp> - 8.4.2-2487
|
|
||||||
- upgrade base version 8.4.1->8.4.2
|
|
||||||
|
|
||||||
* Fri Dec 8 2009 KaiGai Kohei <kaigai@kaigai.gr.jp> - 8.4.1-2464
|
|
||||||
- rework: backport features from v8.5devel tree
|
|
||||||
- fixbug: selinux netlink receiver process didn't have correct ps display
|
|
||||||
|
|
||||||
* Fri Sep 11 2009 KaiGai Kohei <kaigai@kaigai.gr.jp> - 8.4.1-2305
|
|
||||||
- Upgrade base SE-PostgreSQL v8.4.0->v8.4.1
|
|
||||||
- rework: backport features from v8.5devel tree
|
|
||||||
|
|
||||||
* Fri Aug 21 2009 Tomas Mraz <tmraz@redhat.com> - 8.4.0-2238
|
|
||||||
- rebuilt with new openssl
|
|
||||||
|
|
||||||
* Wed Aug 19 2009 KaiGai Kohei <kaigai@kaigai.gr.jp> - 8.4.0-2237
|
|
||||||
- Upgrade SE-PostgreSQL to 8.4.x series
|
|
||||||
|
|
||||||
* Sun Jul 26 2009 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 8.3.7-1991
|
|
||||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild
|
|
||||||
|
|
||||||
* Tue Jun 9 2009 KaiGai Kohei <kaigai@kaigai.gr.jp> - 8.3.7-1990
|
|
||||||
- backport features from v8.4devel, it also needs libselinux-2.0.80
|
|
||||||
|
|
||||||
* Fri Apr 17 2009 KaiGai Kohei <kaigai@kaigai.gr.jp> - 8.3.7-1772
|
|
||||||
- bugfix: /etc/init.d/sepostgresql initdb didn't work correctly
|
|
||||||
|
|
||||||
* Fri Mar 27 2009 KaiGai Kohei <kaigai@kaigai.gr.jp> - 8.3.7-1770
|
|
||||||
- upgrade base PostgreSQL versin 8.3.6->8.3.7
|
|
||||||
- backport features from v8.4devel
|
|
||||||
|
|
||||||
* Thu Feb 26 2009 KaiGai Kohei <kaigai@kaigai.gr.jp> - 8.3.6-2.1635
|
|
||||||
- bugfix: possible information leak by the order of permission checks
|
|
||||||
in row level permission checks.
|
|
||||||
|
|
||||||
* Wed Feb 25 2009 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 8.3.6-3.1518
|
|
||||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild
|
|
||||||
|
|
||||||
* Fri Feb 6 2009 <kaigai@kaigai.gr.jp> - 8.3.6-2.1523
|
|
||||||
- upgrade base PostgreSQL version 8.3.5->8.3.6
|
|
||||||
- backport features from 8.4devel tree
|
|
||||||
- security policy fix for Fedora 9
|
|
||||||
|
|
||||||
* Sat Jan 17 2009 Tomas Mraz <tmraz@redhat.com> - 8.3.5-2.1183
|
|
||||||
- rebuild with new openssl
|
|
||||||
|
|
||||||
* Wed Nov 5 2008 <kaigai@kaigai.gr.jp> - 8.3.5-2.1182
|
|
||||||
- upgrade base PostgreSQL version 8.3.4->8.3.5
|
|
||||||
- backport cumulative bugfixes from 8.4devel series
|
|
||||||
|
|
||||||
* Thu Oct 2 2008 <kaigai@kaigai.gr.jp> - 8.3.4-2.1076
|
|
||||||
- bugfix: "(null)" audit logs for non-cached decision making.
|
|
||||||
- A hook is added for "COPY TO/FROM <file>" cases.
|
|
||||||
|
|
||||||
* Sat Sep 27 2008 <kaigai@kaigai.gr.jp> - 8.3.4-2.1066
|
|
||||||
- update base version to 8.3.4
|
|
||||||
- sepostgresql.pp was marked as obsolute
|
|
||||||
|
|
||||||
* Tue Sep 23 2008 <kaigai@kaigai.gr.jp> - 8.3.3-2.1043
|
|
||||||
- bugfix: a case when INSERT a FK reference to invisible PK
|
|
||||||
|
|
||||||
* Wed Aug 13 2008 <kaigai@kaigai.gr.jp> - 8.3.3-2.964
|
|
||||||
- bugfix: trusted procedure invokation
|
|
||||||
|
|
||||||
* Fri Jul 11 2008 <kaigai@kaigai.gr.jp> - 8.3.3-2.952
|
|
||||||
- Security policy module updates
|
|
||||||
|
|
||||||
* Fri Jul 11 2008 <kaigai@kaigai.gr.jp> - 8.3.3-2.945
|
|
||||||
- Add OpenSSL support
|
|
||||||
- backport 8.4devel fixes
|
|
||||||
|
|
||||||
* Sun Jun 15 2008 <kaigai@kaigai.gr.jp> - 8.3.3-2.889
|
|
||||||
- backport 8.4devel features.
|
|
||||||
|
|
||||||
* Fri Jun 13 2008 <kaigai@kaigai.gr.jp> - 8.3.3-2.869
|
|
||||||
- upgrade base PostgreSQL 8.3.1 -> 8.3.3
|
|
||||||
|
|
||||||
* Wed Apr 30 2008 <kaigai@kaigai.gr.jp> - 8.3.1-2.197
|
|
||||||
- Inconsistent version number format at Changelogs
|
|
||||||
|
|
||||||
* Wed Apr 30 2008 <kaigai@kaigai.gr.jp> - 8.3.1-2.196
|
|
||||||
- BUGFIX: ROW-level control did not work correctly on TRUNCATE
|
|
||||||
|
|
||||||
* Sun Mar 9 2008 <kaigai@kaigai.gr.jp> - 8.3.0-2.129
|
|
||||||
- BUGFIX: more conprehensive fixes in "SELECT COUNT(*) ..."
|
|
||||||
|
|
||||||
* Sun Mar 2 2008 <kaigai@kaigai.gr.jp> - 8.3.0-2.120
|
|
||||||
- BUGFIX: CREATE TABLE statement with explicit labeled columns
|
|
||||||
- BUGFIX: SELECT count(*) does not filter unallowed tuples
|
|
||||||
|
|
||||||
* Wed Feb 27 2008 <kaigai@kaigai.gr.jp> - 8.3.0-2.117
|
|
||||||
- ".beta" removed.
|
|
||||||
|
|
||||||
* Wed Feb 27 2008 <kaigai@kaigai.gr.jp> - 8.3.0-2.114
|
|
||||||
- Security policy updates
|
|
||||||
|
|
||||||
* Tue Feb 26 2008 <kaigai@kaigai.gr.jp> - 8.3.0-2.113
|
|
||||||
- BUGFIX: CREATE/ALTER TABLE with CONTEXT='...' did nothing.
|
|
||||||
|
|
||||||
* Thu Feb 7 2008 <kaigai@kaigai.gr.jp> - 8.3.0-2.108
|
|
||||||
- add /etc/logrotate.d/sepostgresql
|
|
||||||
|
|
||||||
* Thu Feb 7 2008 <kaigai@kaigai.gr.jp> - 8.3.0-2.105
|
|
||||||
- update base version to stable 8.3.0
|
|
||||||
- add tzdata dependency
|
|
||||||
- allow db_database:{get_param set_param} for generic domain
|
|
||||||
- error message cleanups
|
|
||||||
- Improve large object hooks in PGACE framework
|
|
||||||
- BUGFIX: db_blob:{drop} was checked at loread()
|
|
||||||
- BUGFIX: incorrect permission in DELETE with RETURNING clause
|
|
||||||
- incorrect permission when we read and update security_context in same time.
|
|
||||||
|
|
||||||
* Fri Jan 25 2008 <kaigai@kaigai.gr.jp> - 8.3RC2-2.62
|
|
||||||
- BUGFIX: add handling to invalid contexts already stored
|
|
||||||
|
|
||||||
* Tue Jan 22 2008 <kaigai@kaigai.gr.jp> - 8.3RC2-2.56
|
|
||||||
- BUGFIX: lack of locks when refering buffer pages at update/delete hooks
|
|
||||||
- BUGFIX: explicit labeling using SELECT ... INTO statement.
|
|
||||||
|
|
||||||
* Sun Jan 20 2008 <kaigai@kaigai.gr.jp> - 8.3RC2-2.52
|
|
||||||
- shares /usr/lib/pgsql/*.so libraries, with original postgresql.
|
|
||||||
|
|
||||||
* Thu Jan 10 2008 <kaigai@kaigai.gr.jp> - 8.3RC1-2.37
|
|
||||||
- add sepg_dump/sepg_dumpall support for 8.3base package.
|
|
||||||
|
|
||||||
* Mon Nov 26 2007 <kaigai@kaigai.gr.jp> - 8.3beta3-2.0
|
|
||||||
- Branch from 8.2.x tree
|
|
||||||
|
|
||||||
* Wed Nov 21 2007 <kaigai@kaigai.gr.jp> - 8.2.5-1.66
|
|
||||||
- Add a policy module hotfix for labeled networking
|
|
||||||
|
|
||||||
* Thu Nov 1 2007 <kaigai@kaigai.gr.jp> - 8.2.5-1.51
|
|
||||||
- Re-organize repository to prepare to branch 8.3.x based tree.
|
|
||||||
(no differences from 8.2.5-1.33)
|
|
||||||
|
|
||||||
* Wed Oct 17 2007 <kaigai@kaigai.gr.jp> - 8.2.5-1.33
|
|
||||||
- Fix bug: security context was not canonicalized
|
|
||||||
when irregular context (but interpretable) was inputed.
|
|
||||||
|
|
||||||
* Mon Oct 15 2007 <kaigai@kaigai.gr.jp> - 8.2.5-1.31
|
|
||||||
- Fix bug: type definitions of security_label_to_text()
|
|
||||||
and text_to_security_label() are mismatched.
|
|
||||||
|
|
||||||
* Sat Sep 22 2007 <kaigai@kaigai.gr.jp> - 8.2.5-1.23
|
|
||||||
- update base PostgreSQL to 8.2.5
|
|
||||||
|
|
||||||
* Mon Sep 1 2007 <kaigai@kaigai.gr.jp> - 8.2.4-1.0
|
|
||||||
- mark as SE-PostgreSQL 8.2.4-1.0
|
|
||||||
|
|
||||||
* Thu Aug 28 2007 <kaigai@kaigai.gr.jp> - 8.2.4-0.434.beta
|
|
||||||
- add Requires: postgresql-server, instead of Conflicts: tag
|
|
||||||
(Some sharable files are removed from sepostgresql package)
|
|
||||||
|
|
||||||
* Fri Aug 24 2007 <kaigai@kaigai.gr.jp> - 8.2.4-0.429.beta
|
|
||||||
- add policycoreutils to Requires(post/postun)
|
|
||||||
- upstreamed selinux-policy got SE-PostgreSQL related object classes definition.
|
|
||||||
|
|
||||||
* Sat Aug 18 2007 <kaigai@kaigai.gr.jp> - 8.2.4-0.427.beta
|
|
||||||
- sepg_dumpall uses /usr/bin/sepg_dump
|
|
||||||
|
|
||||||
* Fri Aug 17 2007 <kaigai@kaigai.gr.jp> - 8.2.4-0.423.beta
|
|
||||||
- fix policy not to execute sepgsql_user_proc_t from administrative domain
|
|
||||||
|
|
||||||
* Fri Aug 10 2007 <kaigai@kaigai.gr.jp> - 8.2.4-0.418.beta
|
|
||||||
- object classes are renamed with "db_" prefix
|
|
||||||
- /etc/init.d/sepostgresql script is improved.
|
|
||||||
|
|
||||||
* Thu Aug 2 2007 <kaigai@kaigai.gr.jp> - 8.2.4-0.409.beta
|
|
||||||
- specfile updated based on the following comments
|
|
||||||
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=249522#c5
|
|
||||||
|
|
||||||
* Mon Jul 30 2007 <kaigai@kaigai.gr.jp> - 8.2.4-0.407.beta
|
|
||||||
- fix spec file based on Fedora reviewing process
|
|
||||||
- add rawhide support
|
|
||||||
|
|
||||||
* Mon Jul 23 2007 <kaigai@kaigai.gr.jp> - 8.2.4-0.402.beta
|
|
||||||
- add manpage of sepostgresql
|
|
||||||
- fix specfile convention for Fedora suitable
|
|
||||||
|
|
||||||
* Sun Jul 15 2007 <kaigai@kaigai.gr.jp> - 8.2.4-0.398.beta
|
|
||||||
- SECCLASS_DATABASE is updated (fc7->62, fc6->61)
|
|
||||||
|
|
||||||
* Sun Jul 1 2007 <kaigai@kaigai.gr.jp> - 8.2.4-0.391.beta
|
|
||||||
- Mark as a beta version.
|
|
||||||
|
|
||||||
* Sat Jun 30 2007 <kaigai@kaigai.gr.jp> - 8.2.4-0.384.alpha
|
|
||||||
- add fallback context support with $SEPGSQL_FALLBACK_CONTEXT
|
|
||||||
- add sepgsql_enable_users_ddl boolean to restrict sepgsql_sysobj_t
|
|
||||||
- BUGFIX: incorrect inherited attribute expanding for RECORD type (attno=0)
|
|
||||||
- BUGFIX: trigger functions were not checked in COPY FROM statement
|
|
||||||
|
|
||||||
* Tue Jun 26 2007 <kaigai@kaigai.gr.jp> - 8.2.4-0.376.alpha
|
|
||||||
- add pgaceExecutorStart() to hook ExecutorStart()
|
|
||||||
|
|
||||||
* Mon Jun 25 2007 <kaigai@kaigai.gr.jp> - 8.2.4-0.372.alpha
|
|
||||||
- add table name prefix for column name on audit messages
|
|
||||||
- use security_label_raw_in as an alternative for security_label_in
|
|
||||||
- add hook for query execution path with SPI_ interface
|
|
||||||
- add trigger function suppoer
|
|
||||||
- BUGFIX: remove unnecessary checks for COPY TO/FROM on non-table relation
|
|
||||||
- BUGFIX: remove unnecessary checks for LOCK on non-table relation
|
|
||||||
- BUGFIX: incorrect object id for tuples within pg_security
|
|
||||||
- BUGFIX: CommandCounterIncrement() might be called during heap_create_with_catalog.
|
|
||||||
- BUGFIX: correct self-deadlock
|
|
||||||
- update security policy: sepgsql_sysobj_t, sepgsql_user_proc_t, sepgsql_ro_blob_t
|
|
||||||
|
|
||||||
* Tue Jun 19 2007 <kaigai@kaigai.gr.jp> - 8.2.4-0.351.alpha
|
|
||||||
- BUGFIX: sepgsql_compute_avc_datum() accessed userspace AVC without
|
|
||||||
holding any lock.
|
|
||||||
- improve build scripts.
|
|
||||||
|
|
||||||
* Sat Jun 16 2007 <kaigai@kaigai.gr.jp> - 8.2.4-0.320.alpha
|
|
||||||
- update: sepostgresql.pp security policy fot strict/mls suitable
|
|
||||||
- BUGFIX: column:drop evaluation for ALTER TABLE tbl DROP col; statement
|
|
||||||
- add --enable-security option for pg_dumpall command
|
|
||||||
- add {use} permission for table/column/tuple object classes
|
|
||||||
|
|
||||||
* Tue May 29 2007 <kaigai@kaigai.gr.jp> - 8.2.4-0.306.alpha
|
|
||||||
- BUGFIX: RangeTblEntry->requiredPerms are polluted.
|
|
||||||
|
|
||||||
* Sun May 27 2007 <kaigai@kaigai.gr.jp> - 8.2.4-0.304.alpha
|
|
||||||
- add support for dynamic object class/access vector mapping
|
|
||||||
- BUGFIX: Lack of implicit labeling on COPY FROM statement for system catalogs
|
|
||||||
- BUGFIX: Incorrect security context handling for inherited tables
|
|
||||||
|
|
||||||
* Fri May 25 2007 <kaigai@kaigai.gr.jp> - 8.2.4-0.292.alpha
|
|
||||||
- add pg_dump/pg_dumpall/pg_restore with --enable-security option
|
|
||||||
- add support on OUTER JOIN by rewriting query.
|
|
||||||
- add security_context support on COPY TO/FROM statement
|
|
||||||
- add unlabeled security context support (enable to obtain /selinux/initial_contexts/*)
|
|
||||||
- BUGFIX: lack of checks on JOIN ON condition
|
|
||||||
- BUGFIX: pseudo relation object (sequence, toast, ...) are not handled as database obj.
|
|
||||||
- BUGFIX: lack of tuple:insert checks at COPY FROM statement
|
|
||||||
- BUGFIX: server crash when CREATE TABLE command with newly defined CONTEXT = '...'.
|
|
||||||
|
|
||||||
* Wed May 16 2007 <kaigai@kaigai.gr.jp> - 8.2.4-0.266.alpha
|
|
||||||
- BUGFIX: incorrect security context of newly generated system object.
|
|
||||||
- BUGFIX: missing error text when audit log is disabled.
|
|
||||||
- BUGFIX: incorrect Oid of newly generated tuples within pg_security.
|
|
||||||
- BUGFIX: sepgsql_enable_audittuple is misconditioned.
|
|
||||||
- add checks for T_RowExpr/T_RowCompareExpr/T_BooleanTest
|
|
||||||
T_DistinctExpr/T_ConvertRowtypeExpr
|
|
||||||
- add support CONTEXT = 'xxx' for CREATE TABLE/FUNCTION/DATABASE statement
|
|
||||||
|
|
||||||
* Sun Apr 30 2007 <kaigai@kaigai.gr.jp> - 8.2.4-0.240.alpha
|
|
||||||
- update base version 8.2.3 -> 8.2.4
|
|
||||||
- BUGFIX: unexpected expose in OUTER JOIN statement.
|
|
||||||
add rewrite OUTER JOIN into SUBQUERY to ensure filtering violated tuples.
|
|
||||||
- BUGFIX: strange operation in text_to_security_label()
|
|
||||||
- BUGFIX: infinite recursive call on security label -> oid mapping
|
|
||||||
- BUGFIX: sepgsql_avc_init() is called in policy state monitoring process
|
|
||||||
to avoid nonsense initialization of avc_shmem.
|
|
||||||
|
|
||||||
* Fri Apr 27 2007 <kaigai@kaigai.gr.jp> - 8.2.3-0.232.alpha
|
|
||||||
- object class numbers were redefined. (SECCLASS_DATABASE got into 61)
|
|
||||||
- is_selinux_enabled() was cached on the shared memory segment.
|
|
||||||
- BUGFIX: server went into infinit loop on foreign key constraint.
|
|
||||||
|
|
||||||
* Mon Apr 16 2007 <kaigai@kaigai.gr.jp> - 8.2.3-0.226.alpha
|
|
||||||
- BUGFIX: cases when several variables with same type in a single table
|
|
||||||
|
|
||||||
* Sat Apr 07 2007 <kaigai@kaigai.gr.jp> - 8.2.3-0.214.alpha
|
|
||||||
- add the first implementation of SE-PostgreSQL on PGACE framework
|
|
||||||
|
|
||||||
* Wed Mar 21 2007 <kaigai@kaigai.gr.jp> - 8.2.3-0.212.alpha
|
|
||||||
- BUGFIX: SetOperation didn't handle its subquery correctly.
|
|
||||||
So, it caused server crash.
|
|
||||||
|
|
||||||
* Wed Mar 07 2007 <kaigai@kaigai.gr.jp> - 8.2.3-0.209.alpha
|
|
||||||
- BUGFIX: var->varlevelsup was ignored, so outer references
|
|
||||||
from subqueries cause a fault.
|
|
||||||
|
|
||||||
* Tue Feb 27 2007 <kaigai@kaigai.gr.jp> - 8.2.3-0.178.alpha
|
|
||||||
- Initial RPM build
|
|
||||||
1
sources
1
sources
|
|
@ -1 +0,0 @@
|
||||||
56386ded2d5dcd8a4ceef0da81c3d22c postgresql-9.0.3.tar.gz
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue