unpriv user domain <--> SE-PostgreSQL

KaiGai Kohei kaigai at ak.jp.nec.com
Tue Jun 24 02:45:38 UTC 2008


Dan,

At the selinux-policy-3.4.2, you pulled the latest upstreamed
refpolicy which contains a set of SE-PostgreSQL policies,
but it neglected to merge an interface invocation at
userdom_unpriv_user_template(), as follows:

    optional_policy(`
            postgresql_userdom_template($1,$1_t,$1_r)
    ')

It prevents user_t, staff_t, ... to access SE-PostgreSQL.

Could you update it?

Thanks,
-- 
OSS Platform Development Division, NEC
KaiGai Kohei <kaigai at ak.jp.nec.com>




More information about the selinux mailing list