From James.Gates@sun.com Wed Jun 10 12:20:01 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n5AJK1DF012338
	for <LSARC-ext@sac.sfbay.sun.com>; Wed, 10 Jun 2009 12:20:01 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n5AJK0tb016410
	for <@sunmail2sca.sfbay.sun.com:lsarc-ext@sun.com>; Wed, 10 Jun 2009 12:20:01 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KL10020BF1CQO00@brm-avmta-1.central.sun.com> for lsarc-ext@sun.com
 (ORCPT lsarc-ext@sun.com); Wed, 10 Jun 2009 13:20:00 -0600 (MDT)
Received: from gmp-eb-inf-2.sun.com ([192.18.6.24])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KL100MMSF1BLI10@brm-avmta-1.central.sun.com> for
 lsarc-ext@sun.com (ORCPT lsarc-ext@sun.com); Wed,
 10 Jun 2009 13:20:00 -0600 (MDT)
Received: from fe-emea-09.sun.com (gmp-eb-lb-1-fe3.eu.sun.com [192.18.6.10])
	by gmp-eb-inf-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n5AJJxGn027966	for
 <lsarc-ext@sun.com>; Wed, 10 Jun 2009 19:19:59 +0000 (GMT)
Received: from conversion-daemon.fe-emea-09.sun.com by fe-emea-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 id <0KL100J00EPC9D00@fe-emea-09.sun.com> for lsarc-ext@sun.com
 (ORCPT lsarc-ext@sun.com); Wed, 10 Jun 2009 20:19:59 +0100 (BST)
Received: from [192.168.1.100] ([unknown] [208.50.112.239])
 by fe-emea-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 with ESMTPSA id <0KL1008TDF15DJE0@fe-emea-09.sun.com> for lsarc-ext@sun.com
 (ORCPT lsarc-ext@sun.com); Wed, 10 Jun 2009 20:19:58 +0100 (BST)
Date: Wed, 10 Jun 2009 15:19:52 -0400
From: James Gates <James.Gates@sun.com>
Subject: Integrate PostgreSQL version 8.4 into Solaris [LSARC/2009/349
 FastTrack timeout 06/18/2009]
Sender: James.Gates@sun.com
To: lsarc-ext@sun.com
Cc: Zdenek Kotala <Zdenek.Kotala@sun.com>
Message-id: <4A300758.1010601@sun.com>
Organization: Sun Microsystems
MIME-version: 1.0
Content-type: multipart/mixed; boundary="Boundary_(ID_UvpYxzJRH7IqOhEBuUHmXw)"
X-PMX-Version: 5.4.1.325704
User-Agent: Thunderbird 2.0.0.21 (X11/20090323)
Status: RO
Content-Length: 42946

This is a multi-part message in MIME format.

--Boundary_(ID_UvpYxzJRH7IqOhEBuUHmXw)
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT

I've attached the fast track proposal and a completed FOSS checklist (LSARC/2008/061). This case does not qualify for self review as there are several "ARC review required" answers in the checklist. But I've added an explanation beneath each of these answers.

All questions can come to me. Timeout is set for next Thursday (18th).

Thanks, Jim.

-- 
Jim Gates                    Sun Microsystems
Nashua, NH, USA          http://sun.com/postgresql

--Boundary_(ID_UvpYxzJRH7IqOhEBuUHmXw)
Content-type: text/plain; name=PostgreSQL-8.4-one-pager.txt
Content-transfer-encoding: 7BIT
Content-disposition: inline; filename=PostgreSQL-8.4-one-pager.txt

Template Version: @(#)onepager.txt 1.35 07/11/07 SMI
Copyright 2007 Sun Microsystems

1. Introduction
   1.1. Project/Component Working Name:

        Integrate PostgreSQL version 8.4 into Solaris

   1.2. Name of Document Author/Supplier:

        James Gates

   1.3. Date of This Document:
	
        06/10/09
	
	1.3.1. Date this project was conceived:
		
            04/06/09

   1.4. Name of Major Document Customer(s)/Consumer(s):
	1.4.1. The PAC or CPT you expect to review your project:
		
            Database PAC

	1.4.2. The ARC(s) you expect to review your project:

            LSARC

	1.4.3. The Director/VP who is "Sponsoring" this project:

            chris.armes@sun.com

	1.4.4. The name of your business unit:

            Systems/Software/Sustaining Engineering

   1.5. Email Aliases:
    	1.5.1. Responsible Manager: james.gates@sun.com
    	1.5.2. Responsible Engineer: zdenek.kotala@sun.com
    	1.5.3. Marketing Manager: wei-chen.chiu@sun.cOM
	1.5.4. Interest List: sun-postgres-pteam@sun.com,postgresql-techteam@sun.com

2. Project Summary
   2.1. Project Description:

	<Background>

		PostgreSQL 8.1 was integrated into Nevada and Solaris 10
		update 2 after ARC case LSARC/2005/515 was approved in
		March 2006. There were 5 TCAs (all addressed with the
		subsequent integration of 8.2).

	        PostgreSQL 8.2 was integrated into Nevada and Solaris 10
	        update 4 after ARC case LSARC/2006/655 was approved in
	        December 2006.  There were no outstanding TCAs.

		PostgreSQL 8.3 was integrated into Nevada and in Solaris 10
		update 6 after ARC case LSARC/2008/004 was approved in
       		January 2008.  There were no outstanding TCAs.

		PostgreSQL 8.1 was EOF'd by ARC case LSARC/2008/005 in
		May 2008, and removed from Nevada in February 2009.

	</Background>

        This case covers the integration of the next major version (8.4)
	of PostgreSQL.

	Another ARC case for the EOF of PostgreSQL 8.2 will follow
	this case, once it enters it's EOL phase 2.

        The integration of 8.4 qualifies for micro/patch release binding.

   2.2. Risks and Assumptions:
	
        [Modified from the text in LSARC/2008/004 as it's still valid]

        [In the following "8.2", "8.3" or "8.4" without qualification
        refer to the corresponding PostgreSQL version.]

	PostgreSQL is an open source product, and we (Sun) were not involved
	in its development. As in the ARC cases for previous versions,
	we have to make a number of assumptions about its use of stable
	interfaces. However, PostgreSQL is a very mature and stable product
	that has been running on Solaris for many years. So we believe the
	technical risks are low.        

        As was the case with PostgreSQL 8.3 versus 8.2, 8.4 is not
        backwards compatible with 8.3 regarding on-disk data format.
        Currently, an upgrade from 8.3 must be done by doing a dump
        from an 8.3 server, then importing into a new 8.4 database;
        this requires both versions to be available. We added an
	upgrade solution with the integration of 8.3 to mitigate
	this problem (SUNWpostgr-upgrade).

	The business risk of integrating 8.4 is very low, but the risk of
	not integrating it is high - we would be seen as lagging behind the
	community with our releases, and throw into question our commitment
	to releasing and supporting up to date versions of open source
	products.

3. Business Summary

   3.1. Problem Area:
	
        Many customers will need to run a database system, and
        PostgreSQL is a powerful, open source alternative to
        proprietary systems.  By shipping this with Solaris, it's
        ready for use right out of the box.  It's also important that
        new releases of Solaris include a reasonably up-to-date
        version of PostgreSQL.

   3.2. Market/Requester:

	John Loiacono announced support for PostgreSQL on Solaris 10 on
	Nov 17th 2005. See http://news.cnet.com/Sun-backs-open-source-database-PostgreSQL/2100-1014_3-5958850.html. Since then, we've been maintaining
	PostgreSQL in Solaris on a regular basis, and have several customers
	with premium PostgreSQL support contracts.

   3.3. Business Justification:
	
        PostgreSQL is one of the most widely used open sorce database
        systems, but it's most often being run on Linux.  We need to
        show that database solutions can be implemented at a low cost
        also on Solaris, and shipping and supporting PostgreSQL is an
        important part of this.

        Version 8.4 is considered a major release despite the
        seemingly minor numbering. The new features in 8.4
	(versus 8.3) are:

	* Windowing Functions
	* Common Table Expressions & Recursive Joins
	* Default & Variadic parameters for functions
	* Parallel Restore
	* Column Permissions
	* Per-database locale settings
	* Improved hash indexes
	* Improved join performance for EXISTS and NOT EXISTS queries
	* Easier-to-use Warm Standby
	* Free Space Map auto-tuning
	* Visibility Map (reduces vacuum overhead)
	* Version-aware psql (backslash commands)
	* Support SSL certs for user authentication
	* Per-function runtime statistics
	* Easy editing of functions in psql
	* New contrib modules: pg_stat_statements, auto_explain, citext, btree_gin

	The majority of these features are highly desirable to
	enterprise users.

   3.4. Competitive Analysis:
	
        Most LINUX operating systems have PostgreSQL bundled, and
	will include version 8.4 very soon after it's release.

   3.5. Opportunity Window/Exposure:

	PostgreSQL 8.4 is now in the final beta testing stage (beta 2),
	and will likely be available from the community in July 2009
	(no date fixed).  We will make preparations (some have already
	been done) so that we can integrate very soon after the community
	release, provided all paperwork has been completed by then.

        No decision has been made yet whether 8.4 should be integrated
	into Solaris 10.  It is hoped this decision will be made shortly,
	and if so, there should be plently of time to get it into update 9.

   3.6. How will you know when you are done?:
   	
        When the PostgreSQL 8.4 product is integrated into the Nevada
        SFW consolidation.

4. Technical Description:
    4.1. Details:

        [Mostly reused text from the 8.3 ARC case as it also applies
        to 8.4.]

	Version 8.4 will be integrated into the SFW consolidation in the
	same way in which 8.3 was integrated. All the versions will coexist
	in the SFW consolodation, and be issued together with Solaris.

	The complete 8.4 product is modular, and will be packaged in a similar
	fashion to the way version 8.3 is packaged - In that there will be
	separate packages for client tools, server code, development tools,
	docs & man pages, shared libraries and additional server
	procedural languages.

        The version 8.4 packages will have names matching the
        corresponding 8.3 package names:

	SUNWpostgr-84-client		client tools
	SUNWpostgr-84-libs		shared client libraries
	SUNWpostgr-84-server-data-root	database server (Root)
	SUNWpostgr-84-server 		database server (Usr)
	SUNWpostgr-84-contrib		community contributed tools not part
					of core product
	SUNWpostgr-84-devel		development tools and header files
	SUNWpostgr-84-docs		documentation and man pages
	SUNWpostgr-84-pl		additional Perl, Python & TCL server
					procedural languages
	SUNWpostgr-84-tcl		Tcl binding library

	The above 8.4 packages will install files into locations uniquely
	identified by the major version number so that multiple major versions
	can coexist on the same system:

	/usr/postgres/<version>/

		bin	- Commands
		doc	- Documentation (html)
		etc	- Configuration files
		include	- Header files
		lib	- Shared libraries (client & server)
		man	- Man pages (1 & 5)
		share	- SQL files, localized message files, sample config files 

        Under bin and lib there will also be subdirectories amd64 (on
        x86 systems) or sparcv9 (on Sparc systems), with a softlink
        '64' pointing to it; these will contain 64-bit libraries/commands.

	There will also be 2 additional packages delivered with 8.4
	(for which there is no previous equivalent package):

	SUNWpostgr-84-test      PostgreSQL regression test suite
	SUNWpostgr-common	PostgreSQL common version independent files

	SUNWpostgr-84-test contains the comprehensive PostgreSQL regression
	test suite. The package is intended for use by Sun's internal
	QA group, and not for customer use. Therefore it will not be
	included in the default cluster on the Solaris media. Note that the
	regression tests run by this package are not destructive to
	existing data or databases, so customers can safely use the test
	suite if they desire.

	We (Sun) have been working closely with the PostgreSQL community
	for several years now. Some work/contributions we have made are:

	* Introduction of DTrace probes
	* In-place upgrade (work ongoing)
	* Configure option to use the operating system's timezone files

	Recent improvements in 8.4 include:

	* Version independent (backwards compatible) client API library (libpq)
	* Message files uniquely identified by version number in file name

	New package SUNWpostgr-common contains these version independent
	(or backwards compatible) files, which now allows us to install
	into a common (well known) location e.g. /etc, /usr/share.

	The SUNWpostgr-common package will install files into directories

	/etc/postgres
	/usr/bin
	/usr/lib
	/usr/share/locale

        Version 8.2 had an issue with timezone files and whether or
        not to use the ones provided with the community version.  In
        8.3 & 8.4 this is no longer a problem, as the community source
        package now provides a configure option specifically for using
        system timezone files, which is what we do on Solaris.

        For users wanting to upgrade from earlier versions, we have
	provided an upgrade solution.  It comes in a separate package
	called SUNWpostgr-upgrade (integrated with version 8.3) which
	includes a few necessary binaries from the earlier versions
	and a script.

    4.2. Bug/RFE Number(s):
	
        6836044 PostgreSQL 8.4 to be included into the SFW consolidation
	6833794 Upgrade PgAdmin3 to version 1.10
    
    4.3. In Scope:

	PgAdmin3 is the GUI administration tool we supply with PostgreSQL. 
	It's associated ARC case is LSARC/2006/644. The version
	currently integrated with Solaris is 1.8.4. This will be
	upgraded to the latest version (1.10) with the integration
	of PostgreSQL 8.4 as it is needed to support the new 8.4
	features. A seaparate ARC case for the upgrade of PgAdminIII
	from version 1.8.4 to 1.10 is not necessary as it is a minor
	version update (no new interfaces, changes to installation
	locations, and no new packages). Plus version 1.10 is completely
	backwards compatible with version 1.8.4 configuration and data
	files i.e it is a drop-in replacement.

    4.4. Out of Scope:

        A separate ARC case will be raised for the EOF of PostgreSQL 8.2.

    4.5. Interfaces:

        Binaries and libraries are as for PostgreSQL 8.3 except that
        the locations will be under /usr/postgres/8.4 instead of (or
        rather, in addition to) /usr/postgres/8.3.

    4.5.1 Exported Interfaces:

	Interface Name			Classification	Comments
	---------------------------	--------------	------------------------
	SUNWpostgr-84-client		Committed	Package name
	SUNWpostgr-84-libs		Committed	Package name
	SUNWpostgr-84-server-
	data-root			Committed	Package name
	SUNWpostgr-84-server		Committed	Package name
	SUNWpostgr-84-contrib		Committed	Package name
	SUNWpostgr-84-devel		Committed	Package name
	SUNWpostgr-84-docs		Committed	Package name
	SUNWpostgr-84-pl		Committed	Package name
	SUNWpostgr-84-tcl		Committed	Package name
	SUNWpostgr-84-test		Committed	Package name
	SUNWpostgr-common		Committed	Package name

	/etc/postgres			Committed	Installation directory

	/usr/postgres/8.4		Committed	Installation directory
	/usr/postgres/8.4/bin		Committed	Installation directory
	/usr/postgres/8.4/bin/64	Committed	Symlink to
							[amd64|sparcv9]
	/usr/postgres/8.4/bin/amd64	Committed	Installation directory
	/usr/postgres/8.4/bin/sparcv9	Committed	Installation directory
	/usr/postgres/8.4/doc		Committed	Installation directory
	/usr/postgres/8.4/include	Committed	Installation directory
	/usr/postgres/8.4/lib		Committed	Installation directory
	/usr/postgres/8.4/lib/64	Committed	Symlink to
							[amd64|sparcv9]
	/usr/postgres/8.4/lib/amd64	Committed	Installation directory
	/usr/postgres/8.4/lib/sparcv9	Committed	Installation directory
	/usr/postgres/8.4/man		Committed	Installation directory
	/usr/postgres/8.4/share		Committed	Installation directory

	/usr/lib/libpq.so		Uncommitted	Symlink to
							/usr/lib/libpq.so.5
	/usr/lib/libpq.so.5		Uncommitted	Symlink to
							/usr/lib/libpq.so.2
	/usr/lib/libpq.so.5.2		Uncommitted	Symlink to
							/usr/postgres/8.4/lib/libpq.so.5.2
	/usr/lib/libpq.so.5.1		Uncommitted	Symlink to
							/usr/postgres/8.3/lib/libpq.so.5.1
	/usr/lib/libpq.so.5.0		Uncommitted	Symlink to
							/usr/postgres/8.2/lib/libpq.so.5.0
	/usr/lib/libpqxx.so		Uncommitted	Symlink to
							/usr/lib/libpqxx-2.6.9.so
	/usr/lib/libpqxx-2.6.9.so	Uncommitted	Symlink to
							/usr/postgres/8.4/lib/libpqxx-2.6.9.so

	/usr/bin/psql			Uncommitted	Symlink to
							/usr/postgres/8.4/bin/psql
	/usr/share/locale/<locale-name>/LC_MESSAGES/<name-version>.mo
					Uncommitted	Localized message files

    4.5.2 Imported Interfaces:

	Interface Name			Classification	Comments
	---------------------------	--------------	------------------------
	GSSAPI				Committed	PSARC/1996/059 &
							PSARC/2000/039
	libxml				Committed	PSARC/2001/175
	Perl 5.8			Committed	PSARC/1999/192
	zlib				Committed	PSARC/2006/537
	libtcl				Uncommitted	PSARC/2007/317
	libxslt				Uncommitted	PSARC 2002/244
	OpenSSL				Volatile	PSARC/2003/500
	Python 2.4			Volatile	PSARC/2006/666
	Java Runtime Env. 1.6		?		?
	
    4.6. Doc Impact:

	Minimal - Sun will not need to provide any new documentation with the
	product, as there is extensive documentation that accompanies it.

	There is one Sun produced man page that accompanies PostgreSQL;
	postgres_84(5). This man page describes the Sun specific implementation
	e.g. Packages, installation locations, starting & stopping, SMF, RBAC,
	upgrade using SUNWpostgr-upgrade.
    
    4.7. Admin/Config Impact:

        None. There is a GUI admin tool, pgAdmin3, but this has been
        ARCed and integrated independently of this upgrade to the core
        product.
    
    4.8. HA Impact:
	
        There is a Sun Cluster HA agent for managing PostgreSQL databases. This
	is part of the unbundled Sun Cluster product set. The agent is designed
	to be PostgreSQL version independent, so should (in theory) be able to
	manage a new 8.4 database. Note that we shall not be changing or
	removing any earlier versions of PostgreSQL (i.e. 8.3, 8.2), so there
	will be no impact on existing databases or their HA agents.
    
    4.9. I18N/L10N Impact:
	
        PostgreSQL contains many I18N/L10N features, including:

	EUC_JIS_2004/SHIFT_JIS_2004 support
	Multibyte encoding support, incl. UTF8
	Multiple language (locale) support (NLS)
	Database level Collation (new in version 8.4)

    4.10. Packaging & Delivery:

	SUNWpostgr-84-client	PostgreSQL client tools
	SUNWpostgr-84-contrib	PostgreSQL community contributed tools not part of core product
	SUNWpostgr-84-devel	PostgreSQL development tools and header files
	SUNWpostgr-84-docs	PostgreSQL documentation and man pages
	SUNWpostgr-84-libs	PostgreSQL client libraries
	SUNWpostgr-84-pl	PostgreSQL additional Perl, Python & TCL server procedural languages
	SUNWpostgr-84-server	PostgreSQL database server
	SUNWpostgr-84-server-data-root	PostgreSQL database server data directories and root components
	SUNWpostgr-84-tcl	Tcl binding library for PostgreSQL
	SUNWpostgr-84-test	PostgreSQL regression test suite
	SUNWpostgr-common	PostgreSQL common version independent files
  
    4.11. Security Impact:

	PostgreSQL 8.4 will have the same security impact as version 8.3.
	refer to the accompanying PostgreSQL-8.4-FOSS-checklist.txt file
	for further details wrt. security.
    
    4.12. Dependencies:

	The complete set of PostgreSQL 8.4 packages on Nevada are
	dependent upon the following packages:

	SUNWcsl		Core Solaris, (Shared Libs)
	SUNWgss		GSSAPI V2
	SUNWlibC	Sun Workshop Compilers Bundled libC
	SUNWj6rt	JDK 6.0 Runtime Env. (1.6.0_10)
	SUNWlibms	Math & Microtasking Libraries
	SUNWlxml	The XML library
	SUNWlxsl	The XSLT library
	SUNWopenssl	OpenSSL Commands
	SUNWperl584core	Perl 5.8.4 (core)
	SUNWPython	The Python interpreter, libraries and utilities
	SUNWTcl		Tcl - Tool Command Language
	SUNWzlib	The Zip compression library

5. Reference Documents:

	All material associated with the original ARC case to integrate
	PostgreSQL 8.1 can be found at:
	http://sac.sfbay.sun.com/LSARC/2005/515/

        Material associated with the ARC case to integrate PostgreSQL
        8.2 can be found at:
	http://sac.sfbay.sun.com/LSARC/2006/655/

        Material associated with the ARC case to integrate PostgreSQL
        8.3 can be found at:
	http://sac.sfbay.sun.com/LSARC/2008/004/

	PostgreSQL 8.4 information can be found at:
	http://www.postgresql.org/

6. Resources and Schedule:
   6.1. Projected Availability:

        This depends on when the PostgreSQL community formally
        announces 8.4, which is likely to happen in the second half of
        June 2009.

   6.2. Cost of Effort:
	
        Minimal, since it only consist of building and
        packaging, and this can easily be adapted from what was done
        for 8.3.  Also, building and testing has already been done for
        community beta releases.

   6.3. Cost of Capital Resources:
	
        None.

   6.4. Product Approval Committee requested information:
   	6.4.1. Consolidation or Component Name:

		SFW

	6.4.3. Type of CPT Review and Approval expected:

		FastTrack

        6.4.4. Project Boundary Conditions:

		N/A

	6.4.5. Is this a necessary project for OEM agreements:

               No

	6.4.6. Notes:

	6.4.7. Target RTI Date/Release:

               ASAP after the community releases 8.4 (June 2009).

	6.4.8. Target Code Design Review Date:
	6.4.9. Update approval addition:

   6.5. ARC review type:

        FastTrack

   6.6. ARC Exposure:

        open

       6.6.1. Rationale:

              N/A

7. Prototype Availability:
   7.1. Prototype Availability:
	
        N/A

   7.2. Prototype Cost:
	
        N/A

--Boundary_(ID_UvpYxzJRH7IqOhEBuUHmXw)
Content-type: text/plain; name=PostgreSQL-8.4-FOSS-checklist.txt
Content-transfer-encoding: 7BIT
Content-disposition: inline; filename=PostgreSQL-8.4-FOSS-checklist.txt

FCL--FOSS Check List
0.  Introduction
0.1 Document History
    Version   Author             Changes					Date
    0.1       John Fischer       Initial Draft					01/11/2008
    0.2       John Fischer       Modified based upon feedback from ARC members	01/29/2008
    0.3       John Fischer       Modified based upon feedback during committee 	02/12/2008
                                 review
    0.4       John Fischer       Modified based upon SAC review feedback	04/01/2008
    0.5	      John Fischer	 Modified based upon LSARC business meeting	06/10/2008
                                 adding familiarity question and mod dates.
    0.6       John Fischer       Modified based upon user feedback about        06/20/2008
                                 sections that were unanswerable.

0.2 Purpose
    Architecture review at Sun has allowed the company to evolve our projects
    within multiple disjoint groups while still maintaining a cohesive product
    line.  Each architecture review was conducted within Sun's control.  With
    the advent of Free Open Source Software processes the control that Sun as
    a company can wield has been diminished.  Now that Sun is moving to a more
    fluid delivery mechanism with project Indiana we need to evolve the 
    architecture review process.  This document is meant to aid in the 
    architecture review process.  Each new project must complete this check list 
    to help ensure that the overall resulting product conforms to Sun product 
    standards.  If the project deviates from these standards further review 
    would be necessary by an architecture review committee.
    
    After the check list is completed the project team should be able to 
    determine if a project can be automatically approved.  This will occur
    if all checks result in no "ARC review required" answers.  A committee
    member will assist the project team in filing the automatically approved 
    fast track.  An automatically approved fast track is still required in order
    to record the interfaces for future reference.  If the project needs to 
    have further review then follow the regular process for getting projects 
    reviewed.

1.0 Project Information
1.1 Name of project/component

	Integrate PostgreSQL version 8.4 into Solaris

1.2 Author of document

	James Gates

2.0 Project Summary
  2.1 Project Description

	Integration of the next major version (8.4) of PostgreSQL into
	Open Solaris.
  
  2.2 Release binding
      What is is the release binding?
      (see http://opensolaris.org/os/community/arc/policies/release-taxonomy/)
      [ ] Major
      [ ] Minor
      [X] Patch or Micro
      [ ] Unknown -- ARC review required

  2.3 Type of project
      Is this case a Linux Familiarity project?
      [ ] Yes
      [X] No

  2.4 Originating Community
    2.4.1 Community Name

	PostgreSQL - http://www.postgresql.org
    
    2.4.2 Community Involvement
      Indicate Sun's involvement in the community
      [ ] Maintainer
      [X] Contributor
      [ ] Monitoring
      
      Will the project team work with the upstream community to resolve
      architectural issues of interest to Sun?
      [X] Yes 
      [ ] No - briefly explain
      
      Will we or are we forking from the community?
      [ ] Yes - ARC review required prior to forking
      [X] No
      
3.0 Technical Description
  3.1 Installation & Sharable
    3.1.1S Solaris Installation - section only required for Solaris Software
      (see http://opensolaris.org/os/community/arc/policies/install-locations/ for details)
      Does this project follow the Install Locations best practice?
      [X] Yes 
      [ ] No - ARC review required
      
      Does this project install into /usr under [sbin|bin|lib|include|man|share]?
      [X] Yes
      [ ] No or N/A
      
      Does this project install into /opt?
      [ ] Yes - explain below
      [X] No or N/A
      
      Does this project install into a different directory structure?
      [X] Yes - ARC review required
      [ ] No or N/A

	This project installs into /usr/postgres/8.4/[bin|lib|include|man|share] and creates symbolic links (where appropriate) from /usr/bin, /usr/lib, etc.
      
      Do any of the components of this project conflict with anything under /usr?
      (see http://opensolaris.org/os/community/arc/caselog/2007/047/ for details)
      [ ] Yes - explain below
      [X] No
      
      If conflicts exist then will this project install under /usr/gnu?
      [ ] Yes
      [ ] No - ARC review required
      [X] N/A
      
      Is this project installing into /usr/sfw?
      [ ] Yes - ARC review required
      [X] No
      
    3.1.1W Windows Installation - section only required for Windows Software
      (see http://sac.sfbay/WSARC/2002/494 for details)
      Does this project install software into a 
      <system drive>:\Program Files\Sun\<product> or <system drive>:\Sun\<product>
      directory?
      [ ] Yes
      [ ] No - ARC review required
      
      Does the project use the Windows registry?
      [ ] Yes
      [ ] No - ARC review required
      
      Does the project use 
      HKEY_LOCAL_MACHINE\SOFTWARE\Sun Microsystems\<product>\<version>
      for the registry key?
      [ ] Yes
      [ ] No - ARC review required
      
      Is the project's stored location
      HKEY_LOCAL_MACHINE\SOFTWARE\Sun Microsystems\<product id>\<version id>\Path?
      [ ] Yes
      [ ] No - ARC review required
      
    3.1.2 Share and Sharable
      Does the module include any components that are used or shared by 
      other projects?
      [X] Yes
      [ ] No
    
      If yes are these components packaged to be shared with the other FOSS?
      [X] Yes
      [ ] No - ARC review required
      [ ] N/A
    
      Are these components already in the Solaris WOS?
      [X] Yes
      [ ] No - continue with next section (section 3.2)
    
      If yes are these newer versions being delivered?
      [X] Yes
      [ ] No - ARC review required
      
      If yes are the newer versions replacing the existing versions?
      [ ] Yes
      [X] No - ARC review required

	Version depedent files are installed into separate locations e.g.
	/usr/postgres/8.4/*

  3.2 Exported Libraries
      Are libraries being delivered by this project?
      [X] Yes
      [ ] No - continue with next section (section 3.3)
      
      Are 64-bit versions of the libraries being delivered?
      [X] Yes
      [ ] No - ARC review required
    
      Are static versions of the libraries being delivered?
      [ ] Yes - ARC review required
      [X] No 
      
  3.3 Services and the /etc Directory
      (see http://opensolaris.org/os/community/arc/policies/SMF-policy/)
      Does the project integrate anything into /etc/init.d or /etc/rc?.d?
      [ ] Yes - ARC review required
      [X] No
      
      Does the project integrate any new entries into /etc/inittab or
      /etc/inetd.conf?
      [ ] Yes - ARC review required
      [X] No
      
      Does the project integrate any private non-public files into /etc/default
      or /etc/ configuration files?
      [ ] Yes - ARC review required
      [X] No
      
      Does the service manifests method context grant rights above that
      of the noaccess user and basic privilege set?
      [X] Yes - ARC review required
      [ ] No

	The service manifest is executed with credentials user='postgres',
	group='postgres' (which is now a standard user/role on Solaris).
	Both "solaris.smf.value.postgres" & "solaris.smf.manage.postgres"
	authorizations are needed to manage the default services (enable,
	disable, etc.).
        
  3.4 Security
    3.4.1 Secure By Default 
      (see http://opensolaris.org/os/community/arc/policies/secure-by-default/ for details)
      (see http://www.opensolaris.org/os/community/arc/policies/NITS-policy/ for details)
      (see parts of http://opensolaris.org/os/community/arc/policies/SMF-policy/ for
       addtional details)
      Are there any network services provided by this project?
      [X] Yes
      [ ] No - continue with the next section (section 3.4.2)

	When the SMF service is enabled (it's disabled by default), it listens
	on a TCP port (5432 by default) for incoming connections to localhost
	(127.0.0.1) i.e. The database only accepts connections from the local
	server by default.
      
      Are network services enabled by default?
      [ ] Yes - ARC review required
      [X] No
      [ ] N/A
      
      Are network services automatically enabled by the project during installation?
      [ ] Yes - ARC review required
      [X] No
      [ ] N/A

      Are inbound network communications denied by default?
      [X] Yes
      [ ] No - ARC review required
      [ ] N/A
      
      Is inbound data checked to prevent content-based attacks?
      [ ] Yes
      [X] No - ARC review required
      [ ] N/A
      
      Is the outbound receiver authenticated?
      [ ] Yes
      [X] No - ARC review required
      [ ] N/A
      
      Is the receiver authenticated prior to receiving any sensitive outbound communication?
      [ ] Yes
      [X] No - ARC review required
      [ ] N/A

	By default only client connections from the local server are allowed,
	and are trusted implicitely (i.e. no authentication). But remote
	clients can be authenticated using GSSAPI, Kerberos v5, LDAP, SSL
	certificates and PAM services. All data sent/received across the
	network can be encrypted using SSL. Passwords sent/received across
	the network are MD5 encrypted.
      
    3.4.2 Authorization
      (see http://opensolaris.org/os/community/arc/bestpractices/rbac-intro/ and
	   http://opensolaris.org/os/community/arc/bestpractices/rbac-profiles/ and
	   http://opensolaris.org/os/community/arc/bestpractices/rbac-profiles/
           for details)
      Are there any setuid/setgid privileged binaries in the project?
      [ ] Yes - ARC review required
      [X] No - continue with next section (section 3.4.3)
      
      If yes then are the setuid/setgid privileges handled by the use of roles?
      [ ] Yes
      [ ] No - ARC review required

    3.4.3 Auditing
      (see http://opensolaris.org/os/community/arc/policies/audit-policy/ for details)
      (see http://opensolaris.org/os/community/arc/caselog/2003/397 for details)
      Does this component contain administrative or security enforcing software?
      [ ] Yes - ARC review required
      [X] No - continue to next section (section 3.4.4)
      
      (see http://opensolaris.org/os/community/arc/caselog/2003/397 for details)
      Do the components create audit logs detailing what took place including what event
      took place, who was involved, when the event took place?
      [ ] Yes - ARC contract and Audit project team review required
      [ ] No - ARC review required
        
        
    3.4.4 Authentication
      (see http://opensolaris.org/os/community/arc/policies/PAM/)
      Do the components contain any authentication code?
      [X] Yes
      [ ] No - continue to next section (section 3.4.5)
      
      If yes do the components use PAM (plugable authentication modules) for authentication?
      [X] Yes
      [ ] No - ARC review required
      
      If yes is a single PAM session maintained during authentication?
      [X] Yes
      [ ] No - ARC review required
      
      If yes are the components sufficiently privileged to allow the requested 
      operations (authentication, password change, process credential manipulation, 
      audit state initialization)?
      [ ] Yes - briefly describe below
      [X] No - ARC review required

	The PostgreSQL server uses PAM only to validate user name/password
	pairs.
      
    3.4.5 Passwords
      (see http://opensolaris.org/os/community/arc/bestpractices/passwords-cli/ and
           http://opensolaris.org/os/community/arc/bestpractices/passwords-files/ for details)
      Do any of the components for the project deal with passwords?
      [X] Yes
      [ ] No - continue to next section (section 3.4.6)
      
      If yes are these passwords entered via the CLI or environment?
      [X] Yes - ARC review required
      [ ] No

	The CLI does not echo the typed password when prompting, and
	the data is sent to the server md5 encrypted.
      
      Are passwords stored within the file system for the component?
      [X] Yes
      [ ] No - continue to next section (section 3.4.6)
      
      If yes are the permissions on the file such to protect exposing the password(s)?
      [X] Yes
      [ ] No - ARC review required
      
    3.4.6 General Security Questions
      (see http://opensolaris.org/os/community/arc/bestpractices/security-questions/ for details)
      Are there any network protocols used by this project?
      [X] Yes
      [ ] No - continue with the next section (section 3.5)
      
      Do the components use standard network protocols?
      [X] Yes
      [ ] No - ARC review required
      
      Do network services for the project make decisions based upon user, host or 
      service identities?
      [X] Yes - explain below
      [ ] No
      [ ] N/A

	The server uses a configuration file to enforce security rules and
	restrict database access. Each record specifies a connection type,
	a client IP address range (if relevant for the connection type), a
	database name, a user name, and the authentication method to be
	used for connections matching these parameters. The first record
	with a matching connection type, client address, requested database,
	and user name is used to perform authentication.
      
      Do the components make use of secret information during authentication and/or
      authorization?
      [X] Yes - explain below
      [ ] No
      [ ] N/A

	Username/password authentication. But this data is sent over the
	wire md5 encrypted.
  
  3.5 Networking
      Do the components access the network?
      [X] Yes
      [ ] No - continue with the next section (section 3.6)
      
      If yes do the components support IPv6?
      [X] Yes 
      [ ] No - ARC review required
          
  3.6 Core Solaris Components
      Do the components of this project compete with or duplicate core 
      Solaris components?
      [ ] Yes - ARC review required
      [X] No 
      
      Examples of Core Solaris Components include but are not limited to:
      
        Secure By Default
        Authorizations
        PAM -- Plugable Authentication Module
        Privilege
        PRM -- Process Rights Management -- Privilege
        Audit
        xVm -- Virtualization
        zones / Solaris Containers
        PRM -- Process Rights Management
        RBAC -- Role Based Access Control
        TX / Trusted Extensions
        ZFS
        SMF -- Service Management Facility
        FMA -- Fault Management Architecture
        SCF -- Smart Card Facility
        IPsec
        
4.0 Interfaces
  (see http://www.opensolaris.org/os/community/arc/policies/interface-taxonomy/ for details)
  4.1 Exported Interfaces

	Interface Name                  Classification  Comments
        ---------------------------     --------------  ----------------------
	SUNWpostgr-84-client            Committed       Package name
        SUNWpostgr-84-libs              Committed       Package name
        SUNWpostgr-84-server-
        data-root                       Committed       Package name
        SUNWpostgr-84-server            Committed       Package name
        SUNWpostgr-84-contrib           Committed       Package name
        SUNWpostgr-84-devel             Committed       Package name
        SUNWpostgr-84-docs              Committed       Package name
        SUNWpostgr-84-pl                Committed       Package name
        SUNWpostgr-84-tcl               Committed       Package name
        SUNWpostgr-84-test              Committed       Package name
        SUNWpostgr-common               Committed       Package name

        /etc/postgres                   Committed       Installation directory

        /usr/postgres/8.4               Committed       Installation directory
        /usr/postgres/8.4/bin           Committed       Installation directory
        /usr/postgres/8.4/bin/64        Committed       Symlink to
                                                        [amd64|sparcv9]
        /usr/postgres/8.4/bin/amd64     Committed       Installation directory
        /usr/postgres/8.4/bin/sparcv9   Committed       Installation directory
        /usr/postgres/8.4/doc           Committed       Installation directory
        /usr/postgres/8.4/include       Committed       Installation directory
        /usr/postgres/8.4/lib           Committed       Installation directory
        /usr/postgres/8.4/lib/64        Committed       Symlink to
                                                        [amd64|sparcv9]
        /usr/postgres/8.4/lib/amd64     Committed       Installation directory
        /usr/postgres/8.4/lib/sparcv9   Committed       Installation directory
        /usr/postgres/8.4/man           Committed       Installation directory
        /usr/postgres/8.4/share         Committed       Installation directory

        /usr/bin/psql                   Uncommitted     Symlink to
                                                        /usr/postgres/8.4/bin/psql

        /usr/lib/libpq.so               Uncommitted     Symlink to
                                                        /usr/lib/libpq.so.5
        /usr/lib/libpq.so.5             Uncommitted     Symlink to
                                                        /usr/lib/libpq.so.2
        /usr/lib/libpq.so.5.2           Uncommitted     Symlink to
                                                        /usr/postgres/8.4/lib/libpq.so.5.2
        /usr/lib/libpq.so.5.1           Uncommitted     Symlink to
                                                        /usr/postgres/8.3/lib/libpq.so.5.1
        /usr/lib/libpq.so.5.0           Uncommitted     Symlink to
                                                        /usr/postgres/8.2/lib/libpq.so.5.0
        /usr/lib/libpqxx.so             Uncommitted     Symlink to
                                                        /usr/lib/libpqxx-2.6.9.so
        /usr/lib/libpqxx-2.6.9.so       Uncommitted     Symlink to
                                                        /usr/postgres/8.4/lib/libpqxx-2.6.9.so

        /usr/share/locale/<locale-name>/LC_MESSAGES/<name-version>.mo
                                        Uncommitted     Localized message files

  4.2 Imported Interfaces

	Interface Name                  Classification  Comments
        ---------------------------     --------------  ----------------------
        GSSAPI                          Committed       PSARC/1996/059 &
                                                        PSARC/2000/039
        libxml                          Committed       PSARC/2001/175
        Perl 5.8                        Committed       PSARC/1999/192
        zlib                            Committed       PSARC/2006/537
        libtcl                          Uncommitted     PSARC/2007/317
        libxslt                         Uncommitted     PSARC 2002/244
        OpenSSL                         Volatile        PSARC/2003/500
        Python 2.4                      Volatile        PSARC/2006/666
        Java Runtime Env. 1.6           ?               ?
    
          
  Brief Interface Classifications - See Appendix C for definitions
    Volatile - interfaces are fluid and will follow a rapidly changing community
    Uncommitted - interfaces are still evolving in the community and might follow
		  the community
    Committed - interfaces are stable in the community
    Project Private - no review required, just document in table
    Contracted (interface modifier) - further review required

Appendix A - References
  1.  Solaris Installation Locations Policy
      http://opensolaris.org/os/community/arc/policies/install-locations/
  2.  /usr/gnu Installation ARC case
      http://opensolaris.org/os/community/arc/caselog/2007/047/
  3.  Secure By Default Policy
      http://opensolaris.org/os/community/arc/policies/secure-by-default/
  4.  Network Install Time Securityuy Policy
      http://www.opensolaris.org/os/community/arc/policies/NITS-policy/
  5.  Adding RBAC Authorizations Policy
      http://opensolaris.org/os/community/arc/bestpractices/rbac-auths/
  6.  When to use setuid -vs- RBAC roles and profiles
      http://opensolaris.org/os/community/arc/bestpractices/rbac-intro/ and
  7.  Building RBAC Rights Profiles
      http://opensolaris.org/os/community/arc/bestpractices/rbac-profiles/
  8.  Solaris Audit Policy
      http://opensolaris.org/os/community/arc/policies/audit-policy/
  9.  Security questionaire
      http://opensolaris.org/os/community/arc/bestpractices/security-questions/
  10. Interface Taxonomy
      http://www.opensolaris.org/os/community/arc/policies/interface-taxonomy/
  11. Plugable Authentication Modules -- PAM
      http://opensolaris.org/os/community/arc/policies/PAM/
  12. Reusable Passwords In Command Line Arguments and Environment Variables
      http://opensolaris.org/os/community/arc/bestpractices/passwords-cli/
  13. Storing Reusable Passwords on a Filesystem
      http://opensolaris.org/os/community/arc/bestpractices/passwords-files/
  14. Release Taxonomy
      http://opensolaris.org/os/community/arc/policies/release-taxonomy/
  15. Service Management Facility (SMF) usage
      http://opensolaris.org/os/community/arc/policies/SMF-policy/

  
Appendix B - Suggested case materials
  1. man pages
  2. SMF manifests
  3. links to contracts
  
Appendix C - Definitions
Submitter
     an agent responsible for creation of an ARC project along with the
     materials describing that project.
Owner
     the ARC agent responsible for shepherding the case through review
     and ensuring a formal opinion is written where required.
Maintainer
     an agent responsible for releasing new versions of a program, typically
     the "main" contributor or person incharge of making Architectural
     decisions for the project
Contributor
     an agent who make contributions to a project, typically has a voice in
     making Architectural decisions for the project
Monitoring
     an agent who is only following the changes made in the community and
     has no Architectural input into the project
Volatile*
    interfaces that are very fluid and typically follow the originating 
    community.  Typically these interfaces can not be imported by other
    projects.
Uncommitted*
    interfaces that are still evolving but will most likely be present from
    release to release.
Committed*
    interfaces that are stable and with Sun guaranteeing some level of
    compatibility from release to release.
Project Private*
    interfaces that are exposed only to or intended to be used only by
    the project being reviewed.  These interfaces can not be imported by
    other projects.
Not-An-Interface*
    components that are not interfaces.
Contracted* (interface modifier) - ARC review of Contract required
    interfaces that do not allow another project to import can be 

*Note: see http://opensolaris.org/os/community/arc/policies/interface-taxonomy/ for details

--Boundary_(ID_UvpYxzJRH7IqOhEBuUHmXw)--

From James.Gates@sun.com Mon Jun 15 08:33:26 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n5FFXP2t024224
	for <LSARC-ext@sac.sfbay.sun.com>; Mon, 15 Jun 2009 08:33:26 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n5FFXNQg010067
	for <@sunmail2sca.sfbay.sun.com:lsarc-ext@sun.com>; Mon, 15 Jun 2009 09:33:25 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KLA00217DVOMJ00@nwk-avmta-1.sfbay.Sun.COM> for lsarc-ext@sun.com
 (ORCPT lsarc-ext@Sun.com); Mon, 15 Jun 2009 08:33:24 -0700 (PDT)
Received: from gmp-eb-inf-1.sun.com ([192.18.6.21])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KLA00GA3DVN4690@nwk-avmta-1.sfbay.Sun.COM> for
 lsarc-ext@sun.com (ORCPT lsarc-ext@Sun.com); Mon,
 15 Jun 2009 08:33:24 -0700 (PDT)
Received: from fe-emea-09.sun.com (gmp-eb-lb-1-fe3.eu.sun.com [192.18.6.10])
	by gmp-eb-inf-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n5FFXNMK012148	for
 <lsarc-ext@Sun.com>; Mon, 15 Jun 2009 15:33:23 +0000 (GMT)
Received: from conversion-daemon.fe-emea-09.sun.com by fe-emea-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 id <0KLA00B00DRJGX00@fe-emea-09.sun.com> for lsarc-ext@Sun.com
 (ORCPT lsarc-ext@Sun.com); Mon, 15 Jun 2009 16:33:23 +0100 (BST)
Received: from [192.168.1.102] ([unknown] [208.50.112.239])
 by fe-emea-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 with ESMTPSA id <0KLA00DSBDVKU500@fe-emea-09.sun.com> for lsarc-ext@Sun.com
 (ORCPT lsarc-ext@Sun.com); Mon, 15 Jun 2009 16:33:21 +0100 (BST)
Date: Mon, 15 Jun 2009 11:33:20 -0400
From: James Gates <James.Gates@sun.com>
Subject: Re: Integrate PostgreSQL version 8.4 into Solaris [LSARC/2009/349
 FastTrack timeout 06/18/2009]
In-reply-to: <4A319A83.20401@gmail.com>
Sender: James.Gates@sun.com
To: Mark Martin <storycrafter@gmail.com>
Cc: lsarc-ext@sun.com, Zdenek Kotala <Zdenek.Kotala@sun.com>
Message-id: <4A3669C0.8020309@sun.com>
Organization: Sun Microsystems
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <4A300758.1010601@sun.com> <4A319A83.20401@gmail.com>
User-Agent: Thunderbird 2.0.0.21 (X11/20090323)
Status: RO
Content-Length: 1715

EOF of 8.2 is out of scope in this case because:

a) I prefer to submit it as a separate case because then the title can be "EOF of PostgreSQL 8.2", which will be easier for other people to discover (rather than burying the message in the 8.4 case).

b) EOF of 8.2 is not directly related to the integration of 8.4. It's related to our EOL policy - which is time based. 8.2 enters EOL phase 2 in October 2010, and reaches EOSL in Oct 2013. So I have plenty of time to submit the EOF case separately.


Mark Martin wrote:
> James Gates wrote:
>> I've attached the fast track proposal and a completed FOSS checklist 
>> (LSARC/2008/061). This case does not qualify for self review as there 
>> are several "ARC review required" answers in the checklist. But I've 
>> added an explanation beneath each of these answers.
>>
>> All questions can come to me. Timeout is set for next Thursday (18th).
> I took a look and things look fine to me.  Other than a (now) broken 
> link to the old caselog site in your References section, I saw little 
> difference between this and 2008/004 (no surprise).  Why is EOF of 8.2 
> out of scope, though?  Was the EOF of 8.1 predicated on being >2 
> releases old or because the db formats weren't compatible (and/or 
> ENOEASYUPGRADE)?
> I noted that there was approximately 0 discussion on the 8.3 case 
> (2008/004), and no FOSS checklist then.  That saddens me, somewhat, as I 
> am delighted to see Sun actually in lock-step with this particular 
> technology despite 2 very recent DB mergers, and I hope others are at 
> least a little excited about this particular product.

-- 
Jim Gates                    Sun Microsystems
Nashua, NH, USA          http://sun.com/postgresql

