Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 453068 - sys-apps/sandbox: please make it possible to deny writing only
Summary: sys-apps/sandbox: please make it possible to deny writing only
Status: RESOLVED WONTFIX
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: Normal enhancement
Assignee: Sandbox Maintainers
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2013-01-19 23:33 UTC by Michał Górny
Modified: 2017-09-26 10:21 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2013-01-19 23:33:22 UTC
Right now, using 'adddeny' denies both writes and reads. Moreover, following it with 'addread' doesn't help at all. This makes it impossible to restrict the ebuild from overwriting sources while letting it read them.
Comment 1 SpanKY gentoo-dev 2013-01-20 19:30:13 UTC
the default behavior is already to allow reading but disallow writing.  the only way you get write access to a path is to explicitly allow it via `addwrite`.
Comment 2 Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2017-09-26 10:21:03 UTC
This would require PMS changes.