Gentoo Archives: gentoo-dev

From: Matt Turner <mattst88@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] [RFC] Make "seccomp" USE flag global
Date: Sat, 28 Feb 2015 01:48:51
Message-Id: CAEdQ38Gh+m8kYV1ibFge+fckVYQHZuTg7mR9CygCR0qHpOLMoA@mail.gmail.com
In Reply to: Re: [gentoo-dev] [RFC] Make "seccomp" USE flag global by Andrew Savchenko
1 On Fri, Feb 27, 2015 at 5:46 PM, Andrew Savchenko <bircoph@g.o> wrote:
2 > On Sat, 21 Feb 2015 02:44:54 +0300 Andrew Savchenko wrote:
3 >> Hello,
4 >>
5 >> at this moment 8 packages uses "seccomp" flag:
6 >>
7 >> app-admin/clsync
8 >> app-emulation/qemu
9 >> app-emulation/lxc
10 >> net-dns/bind
11 >> net-misc/tlsdate
12 >> net-misc/tor
13 >> net-misc/lldpd
14 >> sys-apps/systemd
15 >>
16 >> for the very same reason: enable seccomp filtering to improve
17 >> security. Some of them use seccomp directly via system calls, while
18 >> other rely on sys-libs/libseccomp, but this should have no
19 >> difference for users.
20 >>
21 >> I propose to add global "seccomp" USE flag as follows:
22 >>
23 >> seccomp - Enable seccomp for system call filtering
24 >>
25 >> and remove local descriptions for affected packages.
26 >>
27 >> Comments?
28 >
29 > Ping.
30 >
31 > If there are no objections, I'll commit the following changes in a
32 > week:
33
34 Seems pretty uncontroversial. FWIW I think you've waited a sufficient
35 amount of time.
36
37 > 1) Add global seccomp flag with description above.
38 > 2) Remove local seccomp descriptions from metadata of the packages
39 > listed above.
40 >
41 > Best regards,
42 > Andrew Savchenko

Replies

Subject Author
Re: [gentoo-dev] [RFC] Make "seccomp" USE flag global Andrew Savchenko <bircoph@g.o>