1 |
On Tue, Feb 11, 2014 at 7:39 AM, Michael Palimaka <kensington@g.o> wrote: |
2 |
> On 02/11/2014 11:34 PM, Rich Freeman wrote: |
3 |
> |
4 |
>> One of those ideas I've always wanted to implement is to create a |
5 |
>> portage hook/patch that looks at the dependencies for the package |
6 |
>> being built and configures sandbox to block read-access to anything |
7 |
>> that wasn't explicitly declared. Sandbox works for read-access as |
8 |
>> well as write-access, though in /etc/sandbox.d/00default read-access |
9 |
>> is enabled everywhere by default. |
10 |
>> |
11 |
>> And, yes, it could be configured to allow access to @system... |
12 |
> That's pretty much what emerge_strict does. |
13 |
|
14 |
What is emerge_strict? The Google is failing me here... |
15 |
|
16 |
Rich |