1 |
On Fri, Feb 27, 2015 at 5:46 PM, Andrew Savchenko <bircoph@g.o> wrote: |
2 |
> On Sat, 21 Feb 2015 02:44:54 +0300 Andrew Savchenko wrote: |
3 |
>> Hello, |
4 |
>> |
5 |
>> at this moment 8 packages uses "seccomp" flag: |
6 |
>> |
7 |
>> app-admin/clsync |
8 |
>> app-emulation/qemu |
9 |
>> app-emulation/lxc |
10 |
>> net-dns/bind |
11 |
>> net-misc/tlsdate |
12 |
>> net-misc/tor |
13 |
>> net-misc/lldpd |
14 |
>> sys-apps/systemd |
15 |
>> |
16 |
>> for the very same reason: enable seccomp filtering to improve |
17 |
>> security. Some of them use seccomp directly via system calls, while |
18 |
>> other rely on sys-libs/libseccomp, but this should have no |
19 |
>> difference for users. |
20 |
>> |
21 |
>> I propose to add global "seccomp" USE flag as follows: |
22 |
>> |
23 |
>> seccomp - Enable seccomp for system call filtering |
24 |
>> |
25 |
>> and remove local descriptions for affected packages. |
26 |
>> |
27 |
>> Comments? |
28 |
> |
29 |
> Ping. |
30 |
> |
31 |
> If there are no objections, I'll commit the following changes in a |
32 |
> week: |
33 |
|
34 |
Seems pretty uncontroversial. FWIW I think you've waited a sufficient |
35 |
amount of time. |
36 |
|
37 |
> 1) Add global seccomp flag with description above. |
38 |
> 2) Remove local seccomp descriptions from metadata of the packages |
39 |
> listed above. |
40 |
> |
41 |
> Best regards, |
42 |
> Andrew Savchenko |