Gentoo Archives: gentoo-dev

From: Andrew Savchenko <bircoph@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] [RFC] Make "seccomp" USE flag global
Date: Sat, 28 Feb 2015 01:46:49
Message-Id: 20150228044631.5f79c865c169e9fd316c066f@gentoo.org
In Reply to: [gentoo-dev] [RFC] Make "seccomp" USE flag global by Andrew Savchenko
1 On Sat, 21 Feb 2015 02:44:54 +0300 Andrew Savchenko wrote:
2 > Hello,
3 >
4 > at this moment 8 packages uses "seccomp" flag:
5 >
6 > app-admin/clsync
7 > app-emulation/qemu
8 > app-emulation/lxc
9 > net-dns/bind
10 > net-misc/tlsdate
11 > net-misc/tor
12 > net-misc/lldpd
13 > sys-apps/systemd
14 >
15 > for the very same reason: enable seccomp filtering to improve
16 > security. Some of them use seccomp directly via system calls, while
17 > other rely on sys-libs/libseccomp, but this should have no
18 > difference for users.
19 >
20 > I propose to add global "seccomp" USE flag as follows:
21 >
22 > seccomp - Enable seccomp for system call filtering
23 >
24 > and remove local descriptions for affected packages.
25 >
26 > Comments?
27
28 Ping.
29
30 If there are no objections, I'll commit the following changes in a
31 week:
32 1) Add global seccomp flag with description above.
33 2) Remove local seccomp descriptions from metadata of the packages
34 listed above.
35
36 Best regards,
37 Andrew Savchenko

Replies

Subject Author
Re: [gentoo-dev] [RFC] Make "seccomp" USE flag global Matt Turner <mattst88@g.o>