Re: [HACKERS] [PATCH] SE-PgSQL/lite (r2429)

2009-11-12 Thread Greg Smith
KaiGai Kohei wrote: In the v8.4 development cycle, I got a suggestion to reduce a burden of reviewer to split off a few functionalities, such as security_context system column and row-level access controls. I lost track of this patch and related bits somewhere along the way, had to triage

Re: [HACKERS] [PATCH] SE-PgSQL/lite (r2429)

2009-11-12 Thread KaiGai Kohei
Greg Smith wrote: KaiGai Kohei wrote: In the v8.4 development cycle, I got a suggestion to reduce a burden of reviewer to split off a few functionalities, such as security_context system column and row-level access controls. I lost track of this patch and related bits somewhere along the

Re: [HACKERS] [PATCH] SE-PgSQL/lite (r2429)

2009-11-12 Thread Greg Smith
KaiGai Kohei wrote: I found a uncertain term in your comment. It seems to me the model has two meanings in this context. - The way to make access control decision (allowed? or denied?). - The granularity of access controls (tables? columns? or tuples?). What I meant by the SEPosgreSQL