1 |
On Thu, Sep 30, 2004 at 04:20:32PM +0000, Luke-Jr wrote: |
2 |
> On Thursday 30 September 2004 2:04 pm, Paul de Vrieze wrote: |
3 |
> > Well, the issue is that without being root the file permissions in the |
4 |
> > install stage will not be correct. The only even more secure option |
5 |
> > besides the sandbox would be some kind of chroot with an overlay |
6 |
> > filesystem. That would though require a nonstandard kernel module and as |
7 |
> > such raise all kinds of other problems. |
8 |
> Simply implementing sandbox as a kernel module would have the same security |
9 |
> effect as such a chroot. Then, libsandbox (or whatever it's called) could |
10 |
> simply use the module if available and fallback to the normal way if it's |
11 |
> not... |
12 |
|
13 |
Well i don't use modules on my servers and i sure wont start |
14 |
using them only for portage. |
15 |
|
16 |
Christian |
17 |
|
18 |
-- |
19 |
gentoo-dev@g.o mailing list |