pgsql: Fix contrib/sepgsql test policy to work with latest SELinux rele

Started by Tom Laneabout 7 years ago1 messagescomitters
Jump to latest
#1Tom Lane
tgl@sss.pgh.pa.us

Fix contrib/sepgsql test policy to work with latest SELinux releases.

As of Fedora 30, it seems that the system-provided macros for setting
up user privileges in SELinux policies don't grant the ability to read
/etc/passwd, as they formerly did. This restriction breaks psql
(which tries to use getpwuid() to obtain the user name it's running
under) and thereby the contrib/sepgsql regression test. Add explicit
specifications that we need the right to read /etc/passwd.

Mike Palmiotto, per a report from me. Back-patch to all supported
branches.

Discussion: /messages/by-id/23856.1563381159@sss.pgh.pa.us

Branch
------
REL9_4_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/0e259d4bc78956c173c9a81c03713e17b6513738

Modified Files
--------------
contrib/sepgsql/sepgsql-regtest.te | 11 +++++++++++
1 file changed, 11 insertions(+)