Gentoo Archives: gentoo-dev

From: Rich Freeman <rich0@g.o>
To: gentoo-dev <gentoo-dev@l.g.o>
Subject: Re: [gentoo-dev] Re: mbox -- looks sort of interesting
Date: Tue, 11 Feb 2014 12:34:10
Message-Id: CAGfcS_nrO0mdm0dcxVaAu5Z0wh377zwpa30gXf2d5-S7JBuvJw@mail.gmail.com
In Reply to: [gentoo-dev] Re: mbox -- looks sort of interesting by Michael Palimaka
1 On Tue, Feb 11, 2014 at 1:56 AM, Michael Palimaka <kensington@g.o> wrote:
2 >
3 > Looks interesting. It reminds me somewhat of autodep[1].
4 >
5
6 Interesting - does this work? I don't see it in portage.
7
8 One of those ideas I've always wanted to implement is to create a
9 portage hook/patch that looks at the dependencies for the package
10 being built and configures sandbox to block read-access to anything
11 that wasn't explicitly declared. Sandbox works for read-access as
12 well as write-access, though in /etc/sandbox.d/00default read-access
13 is enabled everywhere by default.
14
15 And, yes, it could be configured to allow access to @system...
16
17 Rich

Replies

Subject Author
[gentoo-dev] Re: mbox -- looks sort of interesting Michael Palimaka <kensington@g.o>