From mboxrd@z Thu Jan  1 00:00:00 1970
Return-Path: <gentoo-dev+bounces-103124-garchives=archives.gentoo.org@lists.gentoo.org>
Received: from smtp.gentoo.org (woodpecker.gentoo.org [140.211.166.183])
	(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
	 key-exchange X25519 server-signature RSA-PSS (4096 bits))
	(No client certificate requested)
	by finch.gentoo.org (Postfix) with ESMTPS id B23CC1582EF
	for <garchives@archives.gentoo.org>; Wed, 19 Feb 2025 05:03:41 +0000 (UTC)
Received: from lists.gentoo.org (bobolink.gentoo.org [140.211.166.189])
	(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
	 key-exchange X25519 server-signature RSA-PSS (4096 bits))
	(No client certificate requested)
	(Authenticated sender: relay-lists.gentoo.org@gentoo.org)
	by smtp.gentoo.org (Postfix) with ESMTPSA id 95B843431F2
	for <garchives@archives.gentoo.org>; Wed, 19 Feb 2025 05:03:41 +0000 (UTC)
Received: from bobolink.gentoo.org (localhost [127.0.0.1])
	by bobolink.gentoo.org (Postfix) with ESMTP id 529BE110479;
	Wed, 19 Feb 2025 05:02:55 +0000 (UTC)
Received: from smtp.gentoo.org (smtp.gentoo.org [IPv6:2001:470:ea4a:1:5054:ff:fec7:86e4])
	(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
	 key-exchange X25519 server-signature RSA-PSS (4096 bits))
	(No client certificate requested)
	by bobolink.gentoo.org (Postfix) with ESMTPS id 95624110470
	for <gentoo-dev@lists.gentoo.org>; Wed, 19 Feb 2025 05:02:54 +0000 (UTC)
Received: from mail-ed1-f46.google.com (mail-ed1-f46.google.com [209.85.208.46])
	(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
	 key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256)
	(No client certificate requested)
	(Authenticated sender: floppym)
	by smtp.gentoo.org (Postfix) with ESMTPSA id 72BE634314D
	for <gentoo-dev@lists.gentoo.org>; Wed, 19 Feb 2025 05:02:54 +0000 (UTC)
Received: by mail-ed1-f46.google.com with SMTP id 4fb4d7f45d1cf-5e0505275b7so5413210a12.3
        for <gentoo-dev@lists.gentoo.org>; Tue, 18 Feb 2025 21:02:54 -0800 (PST)
X-Gm-Message-State: AOJu0YxJlbt8OflVvMYx1XxW6PQv4I2TEL0IszaEkT6mKXyOj5S4E6hT
	ZtRKTKv8YMQO9Sjj/K4jr31h+IS9I3SlOEptnZF/30cwDvyorguNNLH+l0MHJe8xct4AJIMHtbd
	C4S6XvyVB/cSMguzCBwq0GVqmyvs=
X-Google-Smtp-Source: AGHT+IHzqh7JMxRTxwpweZd/oI3qddSvim/hZn6g2NY34o1Gw27waw3b3dSkM0DiBSg3ie2XXoih7o/QQPQvDfMIcfM=
X-Received: by 2002:a17:907:2d10:b0:ab7:eaf7:2bd6 with SMTP id
 a640c23a62f3a-abbcd0b8f6dmr173910966b.49.1739941371800; Tue, 18 Feb 2025
 21:02:51 -0800 (PST)
Precedence: bulk
List-Post: <mailto:gentoo-dev@lists.gentoo.org>
List-Help: <mailto:gentoo-dev+help@lists.gentoo.org>
List-Unsubscribe: <mailto:gentoo-dev+unsubscribe@lists.gentoo.org>
List-Subscribe: <mailto:gentoo-dev+subscribe@lists.gentoo.org>
List-Id: Gentoo Linux mail <gentoo-dev.gentoo.org>
X-BeenThere: gentoo-dev@lists.gentoo.org
Reply-to: gentoo-dev@lists.gentoo.org
X-Auto-Response-Suppress: DR, RN, NRN, OOF, AutoReply
MIME-Version: 1.0
References: <037e2c8f-2e80-1879-21fd-0d3871897ed4@gentoo.org>
 <d245bb57d954b401fbf8401aeb81c54074d1c9b0.camel@zougloub.eu>
 <dc5ed84b-4b79-3f1d-9668-a59d8fd04585@gentoo.org> <d03f1b31-96d2-ad3c-8d15-b272861aaf91@gentoo.org>
In-Reply-To: <d03f1b31-96d2-ad3c-8d15-b272861aaf91@gentoo.org>
From: Mike Gilbert <floppym@gentoo.org>
Date: Wed, 19 Feb 2025 00:02:40 -0500
X-Gmail-Original-Message-ID: <CAJ0EP42H0mVcfhYe-ihLnsAegG7icwLoJWOmDT0-ObMeBdjWqA@mail.gmail.com>
X-Gm-Features: AWEUYZnPa377MgZ4OcOLKbR5FzGE6BrOsQlHGhVWXJg0Lei5HL9Zf4g2aO0oCxM
Message-ID: <CAJ0EP42H0mVcfhYe-ihLnsAegG7icwLoJWOmDT0-ObMeBdjWqA@mail.gmail.com>
Subject: Re: [gentoo-dev] sandbox and /proc/<pid>/clear_refs [was: problems
 with media-gfx/asymptote]
To: gentoo-dev@lists.gentoo.org
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
X-Archives-Salt: ccf2c86f-808b-45a0-bcfb-e6771cfc753d
X-Archives-Hash: 5148ce242a07712622d78acdec9e980f

On Tue, Feb 18, 2025 at 11:40=E2=80=AFPM Andrey Grozin <grozin@gentoo.org> =
wrote:
>
> Some additional information:
>
> # strace -e trace=3Dfile ./cordtest
> ...
> openat(AT_FDCWD, "/proc/3702/clear_refs", O_WRONLY) =3D 3
> ...
> SUCCEEDED
> +++ exited with 0 +++
>
> It is absolutely legal for the owner of a process to write to
> /proc/<pid>/clear_refs
> I think it is a bug in Gentoo sandbox that this is not allowed.

Please use Bugzilla.