Gentoo Archives: gentoo-hardened

From: Sven Vermeulen <swift@g.o>
To: gentoo-hardened@g.o
Subject: [gentoo-hardened] State of ProPolice
Date: Mon, 05 May 2003 06:29:32
Message-Id: 20030505062931.GD1577@Daikan.pandora.be
1 Hi,
2
3 I know that having the stack protection enabled in Gentoo makes it impossible
4 to use the sandbox facility of Portage. Iirc, the sandbox is to make sure
5 that installing the package will first be done completely in
6 /var/tmp/portage/<package>/build and that no rogue files are placed in the
7 working system immediately, right?
8
9 If so, what happens if you disable sandbox but have userpriv enabled?
10 Won't this give a "Permission denied" where previously a "Sandbox violation"
11 would be raised?
12
13 Wkr,
14 Sven Vermeulen
15
16 --
17 Thanks to DRM, you know that something has been built in environment of
18 unspecified degree of security, from source you cannot check, written by
19 programmers you don't know, released after passing QA of unknown quality and
20 which is released under a license that disclaims any responsibility...