Hello,

Since lately Gentoo devs force you to replace collision-protect with
protect-owned [1] and sometimes packages just spit out files randomly
on the filesystem due to random errors, I thought it may be a good idea
to provide a new feature limiting the locations where packages can
install.

In order to do that, we should first compose a complete include/exclude
list where packages can install. I'd suggest the following:

+ /bin
+ /boot (but maybe just subdirectories so packages can't overwrite
  kernels?)
[potentially + /dev? but that's useful only when tmpfs isn't mounted]
+ /etc
+ /lib, /lib32, /lib64
+ /opt
+ /sbin
[potentially + /service for ugly daemontools]
+ /usr
+ /var
- /usr/local
- /usr/portage

What are your thoughts on this?

[1]:https://bugs.gentoo.org/show_bug.cgi?id=410691#c4

-- 
Best regards,
Michał Górny

Attachment: signature.asc
Description: PGP signature

Reply via email to