1 |
On Sat, 21 Feb 2015 02:44:54 +0300 Andrew Savchenko wrote: |
2 |
> Hello, |
3 |
> |
4 |
> at this moment 8 packages uses "seccomp" flag: |
5 |
> |
6 |
> app-admin/clsync |
7 |
> app-emulation/qemu |
8 |
> app-emulation/lxc |
9 |
> net-dns/bind |
10 |
> net-misc/tlsdate |
11 |
> net-misc/tor |
12 |
> net-misc/lldpd |
13 |
> sys-apps/systemd |
14 |
> |
15 |
> for the very same reason: enable seccomp filtering to improve |
16 |
> security. Some of them use seccomp directly via system calls, while |
17 |
> other rely on sys-libs/libseccomp, but this should have no |
18 |
> difference for users. |
19 |
> |
20 |
> I propose to add global "seccomp" USE flag as follows: |
21 |
> |
22 |
> seccomp - Enable seccomp for system call filtering |
23 |
> |
24 |
> and remove local descriptions for affected packages. |
25 |
> |
26 |
> Comments? |
27 |
|
28 |
Ping. |
29 |
|
30 |
If there are no objections, I'll commit the following changes in a |
31 |
week: |
32 |
1) Add global seccomp flag with description above. |
33 |
2) Remove local seccomp descriptions from metadata of the packages |
34 |
listed above. |
35 |
|
36 |
Best regards, |
37 |
Andrew Savchenko |