Files
flatpak/common
Weng Xuetian 0402e1614c Limit the usage of WAYLAND_SOCKET to an opt-in feature
1. For security context creation, only relies on WAYLAND_DISPLAY, do not
   use WAYLAND_SOCKET since the file descriptor defined by WAYLAND_SOCKET
   can be only consumed once.
2. Due to the incompatiblity between WAYLAND_SOCKET and the security
   context, add a new permission --socket=inherit-wayland-socket
   to limit the usage of WAYLAND_SOCKET to an opt-in feature. Only when
   this flag is set, WAYLAND_SOCKET will be passed to the sandbox.
3. When WAYLAND_SOCKET is not inherited, set FD_CLOEXEC to avoid it to
   be leaked the to sandbox.

Closes: #5614
2024-02-14 19:39:50 +00:00
..
2024-02-13 08:20:57 -06:00
2019-02-25 18:12:30 +00:00
2021-02-09 09:36:59 +01:00
2024-02-13 08:20:57 -06:00
2023-09-04 13:25:32 +01:00
2024-02-13 08:20:57 -06:00
2023-09-04 13:25:32 +01:00
2023-09-04 13:25:32 +01:00
2024-02-13 08:20:57 -06:00
2024-02-13 08:20:57 -06:00
2018-05-24 11:59:52 +00:00
2018-10-08 08:36:23 +00:00
2019-04-08 12:50:42 +00:00