Re: [gentoo-dev] Looking for alternative to RESTRICT=userpriv

2014-07-09 Thread Joshua Kinard
On 07/08/2014 09:25, Michał Górny wrote: > > 3) qmail-related ebuilds that needed to access restricted files (no > details yet). I believe this relates to /var access. qmail is noted in our security guide[1] for its desire to want to install itself into /var/qmail[2], including binaries, libs, e

[gentoo-dev] Looking for alternative to RESTRICT=userpriv

2014-07-08 Thread Michał Górny
Hello, developers. I've been doing some research wrt use of RESTRICT=userpriv [1] lately and found out that most of the affected packages use it solely to gain access to files or devices that are restricted to specific groups. I've specifically noted three cases: 1) ebuilds using CUDA that needed