1 |
On 02/12/2014 01:03 AM, Rich Freeman wrote: |
2 |
> On Tue, Feb 11, 2014 at 7:39 AM, Michael Palimaka <kensington@g.o> wrote: |
3 |
>> On 02/11/2014 11:34 PM, Rich Freeman wrote: |
4 |
>> |
5 |
>>> One of those ideas I've always wanted to implement is to create a |
6 |
>>> portage hook/patch that looks at the dependencies for the package |
7 |
>>> being built and configures sandbox to block read-access to anything |
8 |
>>> that wasn't explicitly declared. Sandbox works for read-access as |
9 |
>>> well as write-access, though in /etc/sandbox.d/00default read-access |
10 |
>>> is enabled everywhere by default. |
11 |
>>> |
12 |
>>> And, yes, it could be configured to allow access to @system... |
13 |
>> That's pretty much what emerge_strict does. |
14 |
> |
15 |
> What is emerge_strict? The Google is failing me here... |
16 |
> |
17 |
> Rich |
18 |
> |
19 |
> |
20 |
Sorry, I should have clarified. It's provided by autodep, extending the |
21 |
dependency analysis by denying access to any files not part of the |
22 |
specified dependencies and @system. |