Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 453068

Summary: sys-apps/sandbox: please make it possible to deny writing only
Product: Gentoo Linux Reporter: Michał Górny <mgorny>
Component: Current packagesAssignee: Sandbox Maintainers <sandbox>
Status: RESOLVED WONTFIX    
Severity: enhancement    
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard:
Package list:
Runtime testing required: ---

Description Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2013-01-19 23:33:22 UTC
Right now, using 'adddeny' denies both writes and reads. Moreover, following it with 'addread' doesn't help at all. This makes it impossible to restrict the ebuild from overwriting sources while letting it read them.
Comment 1 SpanKY gentoo-dev 2013-01-20 19:30:13 UTC
the default behavior is already to allow reading but disallow writing.  the only way you get write access to a path is to explicitly allow it via `addwrite`.
Comment 2 Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2017-09-26 10:21:03 UTC
This would require PMS changes.