Files
flatpak/doc
Weng Xuetian 0402e1614c Limit the usage of WAYLAND_SOCKET to an opt-in feature
1. For security context creation, only relies on WAYLAND_DISPLAY, do not
   use WAYLAND_SOCKET since the file descriptor defined by WAYLAND_SOCKET
   can be only consumed once.
2. Due to the incompatiblity between WAYLAND_SOCKET and the security
   context, add a new permission --socket=inherit-wayland-socket
   to limit the usage of WAYLAND_SOCKET to an opt-in feature. Only when
   this flag is set, WAYLAND_SOCKET will be passed to the sandbox.
3. When WAYLAND_SOCKET is not inherited, set FD_CLOEXEC to avoid it to
   be leaked the to sandbox.

Closes: #5614
2024-02-14 19:39:50 +00:00
..
2020-08-10 15:14:38 +02:00
2020-08-10 15:14:38 +02:00
2020-08-10 15:14:38 +02:00
2020-08-10 15:14:38 +02:00
2020-08-10 15:14:38 +02:00
2020-08-10 15:14:38 +02:00
2020-08-10 15:14:38 +02:00
2022-08-16 10:50:29 +02:00
2020-08-10 15:14:38 +02:00
2020-08-10 15:14:38 +02:00
2022-08-16 10:50:29 +02:00
2022-08-16 10:50:29 +02:00
2020-08-10 15:14:38 +02:00
2020-08-10 15:14:38 +02:00
2020-08-10 15:14:38 +02:00
2022-08-16 10:50:29 +02:00
2020-08-10 15:14:38 +02:00
2020-08-10 15:14:38 +02:00
2022-10-24 16:12:14 +01:00
2022-10-24 16:12:14 +01:00
2017-04-14 10:43:40 -04:00