flatpak: Add --device=all permission
Without --device=all, the sandbox gets a dedicated PTY namespace. Commands run on the host via the HostCommand D-Bus interface receive the file descriptors from the namespaced PTY but cannot determine its path via ttyname(3). This breaks commands like tty(1), ps(1) and emacsclient(1). Add --device=all so the host PTY namespace is used when allocating TTYs. Applications with access to org.freedesktop.Flatpak can already give themselves arbitrary permissions, so the sandboxing benefits of restricted device access are limited. For terminal emulators, the primary benefit of Flatpak is the predictability of the distro-independent target runtime rather than sandboxing.pull/7401/head
parent
dd5d2c5d0b
commit
ae095d2262
|
|
@ -14,6 +14,8 @@ desktop-file-name-suffix: " (Devel)"
|
|||
finish-args:
|
||||
# 3D rendering
|
||||
- --device=dri
|
||||
# use host PTS namespace
|
||||
- --device=all
|
||||
# Windowing
|
||||
- --share=ipc
|
||||
- --socket=fallback-x11
|
||||
|
|
|
|||
|
|
@ -9,6 +9,8 @@ command: ghostty
|
|||
finish-args:
|
||||
# 3D rendering
|
||||
- --device=dri
|
||||
# use host PTS namespace
|
||||
- --device=all
|
||||
# Windowing
|
||||
- --share=ipc
|
||||
- --socket=fallback-x11
|
||||
|
|
|
|||
Loading…
Reference in New Issue