Re: [gentoo-dev] [RFC] Make "seccomp" USE flag global

2015-02-28 Thread Andrew Savchenko
On Fri, 27 Feb 2015 17:48:22 -0800 Matt Turner wrote: [...] > >> I propose to add global "seccomp" USE flag as follows: > >> > >> seccomp - Enable seccomp for system call filtering > >> > >> and remove local descriptions for affected packages. > >> > >> Comments? > > > > Ping. > > > > If there are

Re: [gentoo-dev] [RFC] Make "seccomp" USE flag global

2015-02-27 Thread Matt Turner
On Fri, Feb 27, 2015 at 5:46 PM, Andrew Savchenko wrote: > On Sat, 21 Feb 2015 02:44:54 +0300 Andrew Savchenko wrote: >> Hello, >> >> at this moment 8 packages uses "seccomp" flag: >> >> app-admin/clsync >> app-emulation/qemu >> app-emulation/lxc >> net-dns/bind >> net-misc/tlsdate >> net-misc/tor

Re: [gentoo-dev] [RFC] Make "seccomp" USE flag global

2015-02-27 Thread Andrew Savchenko
On Sat, 21 Feb 2015 02:44:54 +0300 Andrew Savchenko wrote: > Hello, > > at this moment 8 packages uses "seccomp" flag: > > app-admin/clsync > app-emulation/qemu > app-emulation/lxc > net-dns/bind > net-misc/tlsdate > net-misc/tor > net-misc/lldpd > sys-apps/systemd > > for the very same reason:

[gentoo-dev] [RFC] Make "seccomp" USE flag global

2015-02-20 Thread Andrew Savchenko
Hello, at this moment 8 packages uses "seccomp" flag: app-admin/clsync app-emulation/qemu app-emulation/lxc net-dns/bind net-misc/tlsdate net-misc/tor net-misc/lldpd sys-apps/systemd for the very same reason: enable seccomp filtering to improve security. Some of them use seccomp directly via sys