selinux-policy/policy
Chris PeBenito 996779dfad trunk:
The attached patch allows unprivileged clients to export from or import
to the largeobject owned by themselves.

The current security policy does not allow them to import/export any
largeobjects without any clear reason.

NOTE: Export of the largeobject means that it dumps whole of the
largeobject into a local file, so SE-PostgreSQL checks both of
db_blob:{read export} on the largeobject and file:{write} on the
local file. Import is a reversal behavior.

KaiGai Kohei
2009-05-22 13:37:32 +00:00
..
flask se-postgresql update from kaigai 2009-05-07 12:35:32 +00:00
modules trunk: 2009-05-22 13:37:32 +00:00
support trunk: add open perm to sock_file. 2009-03-11 14:58:03 +00:00
constraints trunk: fix role change constraint. 2008-12-03 20:16:08 +00:00
global_booleans trunk: merge strict and targeted policies. merge shlib_t into lib_t. 2007-10-02 16:04:50 +00:00
global_tunables trunk: merge UBAC. 2008-11-05 16:10:46 +00:00
mcs se-postgresql update from kaigai 2009-05-07 12:35:32 +00:00
mls se-postgresql update from kaigai 2009-05-07 12:35:32 +00:00
policy_capabilities trunk: Enable network_peer_controls policy capability from Paul Moore. 2009-02-03 15:45:30 +00:00
rolemap trunk: merge UBAC. 2008-11-05 16:10:46 +00:00
users trunk: drop workaround rules. 2008-07-02 12:17:38 +00:00