diff options
author | Robert Haas <rhaas@postgresql.org> | 2013-03-28 15:38:35 -0400 |
---|---|---|
committer | Robert Haas <rhaas@postgresql.org> | 2013-03-28 15:41:38 -0400 |
commit | 0f05840bf4c256b838eca8f1be9d7b5be82ccd0e (patch) | |
tree | 33f506bd41aad831419e63885a63a2200706344a /doc/src | |
parent | ae7f1c3ef2eef9584e3c9a42c395eb0c0e59a5ed (diff) | |
download | postgresql-0f05840bf4c256b838eca8f1be9d7b5be82ccd0e.tar.gz postgresql-0f05840bf4c256b838eca8f1be9d7b5be82ccd0e.zip |
Allow sepgsql labels to depend on object name.
The main change here is to call security_compute_create_name_raw()
rather than security_compute_create_raw(). This ups the minimum
requirement for libselinux from 2.0.99 to 2.1.10, but it looks
like most distributions will have picked that up before 9.3 is out.
KaiGai Kohei
Diffstat (limited to 'doc/src')
-rw-r--r-- | doc/src/sgml/sepgsql.sgml | 7 |
1 files changed, 4 insertions, 3 deletions
diff --git a/doc/src/sgml/sepgsql.sgml b/doc/src/sgml/sepgsql.sgml index 5ee08e1dee2..7c7f953f919 100644 --- a/doc/src/sgml/sepgsql.sgml +++ b/doc/src/sgml/sepgsql.sgml @@ -63,7 +63,7 @@ <filename>sepgsql</> can only be used on <productname>Linux</productname> 2.6.28 or higher with <productname>SELinux</productname> enabled. It is not available on any other platform. You will also need - <productname>libselinux</> 2.0.99 or higher and + <productname>libselinux</> 2.1.10 or higher and <productname>selinux-policy</> 3.9.13 or higher (although some distributions may backport the necessary rules into older policy versions). @@ -326,8 +326,9 @@ $ sudo semodule -r sepgsql-regtest When <filename>sepgsql</filename> is in use, security labels are automatically assigned to supported database objects at creation time. This label is called a default security label, and is decided according - to the system security policy, which takes as input the creator's label - and the label assigned to the new object's parent object. + to the system security policy, which takes as input the creator's label, + the label assigned to the new object's parent object and optionally name + of the constructed object. </para> <para> |