1 |
On Monday 28 May 2012 14:34:22 Zac Medico wrote: |
2 |
> Hi, |
3 |
> |
4 |
> In case you aren't familiar with FEATURES=userpriv, here's the |
5 |
> description from the make.conf(5) man page: |
6 |
> |
7 |
> Allow portage to drop root privileges and compile packages as |
8 |
> portage:portage without a sandbox (unless usersandbox is also used). |
9 |
> |
10 |
> The rationale for having the separate "usersandbox" setting, to enable |
11 |
> use of sys-apps/sandbox, is that people who enable userpriv sometimes |
12 |
> prefer to have sandbox disabled in order to slightly improve |
13 |
> performance. However, I would recommend to enable usersandbox by |
14 |
> default, for the purpose of logging sandbox violations. |
15 |
> |
16 |
> Note that ebuilds can set RESTRICT="userpriv" if they require superuser |
17 |
> privileges during any of the src_* phases that userpriv affects. |
18 |
> |
19 |
> I've been using FEATURES="userpriv usersandbox" for years, and I don't |
20 |
> remember experiencing any problems because of it, so I think that it |
21 |
> would be reasonable to have it enabled by default. Objections? |
22 |
|
23 |
I'm using usersync since a long time, how about add it too? |
24 |
-- |
25 |
Agostino Sarubbo ago -at- gentoo.org |
26 |
Gentoo/AMD64 Arch Security Liaison |
27 |
GPG: 0x7CD2DC5D |