Gentoo Archives: gentoo-dev

From: Rich Freeman <rich0@g.o>
To: gentoo-dev <gentoo-dev@l.g.o>
Subject: Re: [gentoo-dev] Re: mbox -- looks sort of interesting
Date: Tue, 11 Feb 2014 14:03:20
Message-Id: CAGfcS_nBEZNBcPtcpKrD60+vEQOAxSuzOtByopzk83UGsJThbQ@mail.gmail.com
In Reply to: [gentoo-dev] Re: mbox -- looks sort of interesting by Michael Palimaka
1 On Tue, Feb 11, 2014 at 7:39 AM, Michael Palimaka <kensington@g.o> wrote:
2 > On 02/11/2014 11:34 PM, Rich Freeman wrote:
3 >
4 >> One of those ideas I've always wanted to implement is to create a
5 >> portage hook/patch that looks at the dependencies for the package
6 >> being built and configures sandbox to block read-access to anything
7 >> that wasn't explicitly declared. Sandbox works for read-access as
8 >> well as write-access, though in /etc/sandbox.d/00default read-access
9 >> is enabled everywhere by default.
10 >>
11 >> And, yes, it could be configured to allow access to @system...
12 > That's pretty much what emerge_strict does.
13
14 What is emerge_strict? The Google is failing me here...
15
16 Rich

Replies

Subject Author
[gentoo-dev] Re: mbox -- looks sort of interesting Michael Palimaka <kensington@g.o>