adding -nolisten local to X startup, to allow for better gui isolation.

41 views
Skip to first unread message

pixel fairy

unread,
Sep 11, 2016, 2:47:05 AM9/11/16
to qubes-devel
As explained here, https://github.com/netblue30/firejail/issues/770 adding '-nolisten local' allows for easily isolating x11 or sandboxing an app from it. i cant see any advantage to having both the unix domain socket and the abstract socket. 

this should be upstream. but, that change would take longer, if it even makes it through their bureaucracies.

example, a text based irc client shouldnt take screen shots in the background.
Reply all
Reply to author
Forward
0 new messages