Gentoo Archives: gentoo-dev

From: Alexis Ballier <aballier@g.o>
To: "Michał Górny" <mgorny@g.o>
Cc: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Figuring out the solution to in-network-sandbox distcc
Date: Wed, 21 Jan 2015 15:01:10
Message-Id: 20150121160055.296ace59@gentoo.org
In Reply to: [gentoo-dev] Figuring out the solution to in-network-sandbox distcc by "Michał Górny"
1 On Wed, 21 Jan 2015 11:05:34 +0100
2 Michał Górny <mgorny@g.o> wrote:
3
4 > Hello, developers.
5 >
6 > As you may recall, the main blocker for wide-establishment of
7 > FEATURES=network-sandbox prohibiting network access within the build
8 > environment is distcc. Since all connectivity is disabled, distcc can
9 > no longer reach other distcc servers and build efficiently. I
10 > therefore find it important to figure out a solution.
11 >
12 > I see two generic approaches possible here:
13 >
14 > 1. proxying distcc from within the build environment, or
15 >
16 > 2. moving distcc-spawned processes back to parent's namespace.
17
18 [...]
19
20 >
21 > Any other ideas?
22 >
23
24 I haven't followed this at all, so this might be very stupid:
25 Isn't it possible to whitelist distcc hosts ?
26
27 Alexis.

Replies