Gentoo Archives: gentoo-dev

From: Pacho Ramos <pacho@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] RFC: Enable FEATURES="userpriv usersandbox" by default?
Date: Mon, 02 Jul 2012 19:49:11
Message-Id: 1341258492.10856.2.camel@belkin4
In Reply to: [gentoo-dev] RFC: Enable FEATURES="userpriv usersandbox" by default? by Zac Medico
1 El lun, 28-05-2012 a las 14:34 -0700, Zac Medico escribió:
2 > Hi,
3 >
4 > In case you aren't familiar with FEATURES=userpriv, here's the
5 > description from the make.conf(5) man page:
6 >
7 > Allow portage to drop root privileges and compile packages as
8 > portage:portage without a sandbox (unless usersandbox is also used).
9 >
10 > The rationale for having the separate "usersandbox" setting, to enable
11 > use of sys-apps/sandbox, is that people who enable userpriv sometimes
12 > prefer to have sandbox disabled in order to slightly improve
13 > performance. However, I would recommend to enable usersandbox by
14 > default, for the purpose of logging sandbox violations.
15 >
16 > Note that ebuilds can set RESTRICT="userpriv" if they require superuser
17 > privileges during any of the src_* phases that userpriv affects.
18 >
19 > I've been using FEATURES="userpriv usersandbox" for years, and I don't
20 > remember experiencing any problems because of it, so I think that it
21 > would be reasonable to have it enabled by default. Objections?
22
23 Looks like non important problems arised and, then, these could probably
24 be enabled by default, no? :)

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies