|
|
|
|
|
by dsp_person
452 days ago
|
|
aren't abstract sockets un-jailable unless using network namespaces? or in the other direction, to truly prevent e.g. xorg socket from being accessed by a bubblejailed application, it should exclude --share-net, regardless if you bind the actual path to the socket (since abstract permeates beyond that) |
|
You're telling me there's another reason, then... Can't guess which one.
Hmmm...