Bug 162769 - users can't create/use postgres databases
users can't create/use postgres databases
Status: CLOSED NEXTRELEASE
Product: Fedora
Classification: Fedora
Component: selinux-policy-targeted (Show other bugs)
3
All Linux
medium Severity medium
: ---
: ---
Assigned To: Daniel Walsh
: FutureFeature
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2005-07-08 11:23 EDT by Alexandre Oliva
Modified: 2007-11-30 17:11 EST (History)
0 users

See Also:
Fixed In Version:
Doc Type: Enhancement
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2005-07-19 23:47:17 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Alexandre Oliva 2005-07-08 11:23:10 EDT
Some of my users would like to create their own databases using postgres. 
AFAICT, the targeted policy won't let them do it.  Couldn't they be relaxed
(perhaps with a boolean) so as to enable databases to be created and run in say
users' home dirs, some NFS mounted, some local to the server where they'd run
the database servers?
Comment 1 Daniel Walsh 2005-07-14 12:01:36 EDT
I believe the targeted policy should allow a user to do this.

The postgres application should not transition unless run as a server.
Comment 2 Alexandre Oliva 2005-07-14 23:48:44 EDT
Err...  It certainly doesn't allow a user to run postmaster to have the database
listening on some (non-standard) port, and this is precisely what my user
needed.  I ended up suggesting them to copy the binaries to their own home dir,
such that transitions wouldn't occur and they'd be able to run the servers, but
then, should updates be released, they won't take them automatically, which is
very bad.

Since stopping users from running the database server properly will just lead
them to such undesirable behavior, since they have to get their job done, why
not get the default policy to take care of that already?
Comment 3 Daniel Walsh 2005-07-14 23:56:32 EDT
Ok, I midunderstood,  Could you give me a step by step example of what a user
would do to setup a personal database.  (I have never used postgres before.)
Comment 4 Alexandre Oliva 2005-07-15 01:04:44 EDT
initdb -D ~/mydb # to create the database in ~/mydb
postmaster -D ~/mydb # to start the server

FWIW, this works in FC4 and rawhide, but not in FC3 (as of last Friday).  I
*thought* I'd tested on FC4 as well, and it failed, but since it now works,
maybe I didn't?  Or maybe the recent updates fixed it?

Anyhow, I've changed the but to reflect that the problem affects FC3 only.  This
lowers its priority for me, since I'm very soon rolling FC4 out on the lab.
Comment 5 Daniel Walsh 2005-07-15 13:45:11 EDT
Yes, I was looking at FC4.  In FC3 unconfined_t was transitioning by default on
all targets.  We have removed this in FC4.  It only happens when you start
things via the initscripts.  Seems to more closely match peoples expectations. 
 I really don't want to update FC3 any more, so I will hold off on this until I
have to update it.  FC4 is nice... :^)

Note You need to log in before you can comment on or make changes to this bug.