1 |
On Tue, Feb 11, 2014 at 1:56 AM, Michael Palimaka <kensington@g.o> wrote: |
2 |
> |
3 |
> Looks interesting. It reminds me somewhat of autodep[1]. |
4 |
> |
5 |
|
6 |
Interesting - does this work? I don't see it in portage. |
7 |
|
8 |
One of those ideas I've always wanted to implement is to create a |
9 |
portage hook/patch that looks at the dependencies for the package |
10 |
being built and configures sandbox to block read-access to anything |
11 |
that wasn't explicitly declared. Sandbox works for read-access as |
12 |
well as write-access, though in /etc/sandbox.d/00default read-access |
13 |
is enabled everywhere by default. |
14 |
|
15 |
And, yes, it could be configured to allow access to @system... |
16 |
|
17 |
Rich |