Gentoo Archives: gentoo-dev

From: Georgi Georgiev <chutz@×××.net>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] [RFC] ACCEPT_RESTRICT for questionable values of RESTRICT
Date: Thu, 11 Jan 2007 00:41:27
Message-Id: 20070111093829.8o2canzf0wsc48co@horde.gg3.net
In Reply to: Re: [gentoo-dev] [RFC] ACCEPT_RESTRICT for questionable values of RESTRICT by Ciaran McCreesh
1 Quoting Ciaran McCreesh <ciaranm@×××××××.org>:
2
3 > On Thu, 11 Jan 2007 09:07:54 +0900 Georgi Georgiev <chutz@×××.net>
4 > wrote:
5 > | Further, by adopting ACCEPT_RESTRICT, it would be possible to be able
6 > | to say: ACCEPT_RESTRICT=-sandbox: Do not let any ebuild touch
7 > | anything outside the sandbox.
8 > | ACCEPT_RESTRICT=-userpriv: Do not let any ebuild run with elevated
9 > | privileges.
10 >
11 > Which gains what, exactly? These are not things about which the end
12 > user should be concerned.
13
14 A user shouldn't be concerned if an ebuild wants to leave the sandbox
15 when not supposed to?
16
17 Anyway, I'll agree that this RESTRICT should simply be disallowed and
18 that's about the only thing that bothered me.
19
20
21 ----------------------------------------------------------------
22 This message was sent using IMP, the Internet Messaging Program.
23
24
25 --
26 gentoo-dev@g.o mailing list

Replies

Subject Author
Re: [gentoo-dev] [RFC] ACCEPT_RESTRICT for questionable values of RESTRICT Ciaran McCreesh <ciaranm@×××××××.org>