Created attachment 398962 [details, diff] gentoo-sources-3.19.1-portage-Kconfig.patch Re: RFC: enabling ipc-sandbox & network-sandbox by default, this patch adds an option to the Gentoo menu that enables CGROUPS for cgroup, IPC_NS for ipc-sandbox, and NET_NS for network-sandbox. The first attachment is a patch is against 3.19.1 with 4567_distro-Gentoo-Kconfig.patch already applied. The second is a new 4567_distro-Gentoo-Kconfig.patch.
Created attachment 398964 [details, diff] 4567_distro-Gentoo-Kconfig.patch
There's also TMPFS_XATTR for FEATURES="xattr" which is on by default. Should we include that or is it mainly just for Hardened?
Thanks for the patch. It is appreciated and makes my life easier. I think TMPFS_XATTR is more for hardened.
FEATURES="xattr" is enabled by default only for hardened profiles, by this profile setting: hardened/linux/package.use.force:sys-apps/portage xattr I think it's safe to assume that anyone who needs TMPFS_XATTR can enable it themselves.
Released in 3.19.2.