From mboxrd@z Thu Jan 1 00:00:00 1970 From: Julien Lepiller Subject: bug#34135: IceCat lacks WebGL support Date: Mon, 21 Jan 2019 09:49:43 +0100 Message-ID: <7A88B01C-EAB9-47BA-98EC-16F91C7993E7@lepiller.eu> References: <87o98cr6kx.fsf@gnu.org> <20190119180750.13c17654@lepiller.eu> <87womzlzhm.fsf@gnu.org> <87d0oqe7u2.fsf@elephly.net> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Return-path: Received: from eggs.gnu.org ([209.51.188.92]:47668) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1glVJZ-0005at-LS for bug-guix@gnu.org; Mon, 21 Jan 2019 03:52:18 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1glVHO-0004mp-CF for bug-guix@gnu.org; Mon, 21 Jan 2019 03:50:03 -0500 Received: from debbugs.gnu.org ([209.51.188.43]:40118) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1glVHO-0004mf-8o for bug-guix@gnu.org; Mon, 21 Jan 2019 03:50:02 -0500 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1glVHN-0004qM-Vy for bug-guix@gnu.org; Mon, 21 Jan 2019 03:50:02 -0500 Sender: "Debbugs-submit" Resent-Message-ID: In-Reply-To: <87d0oqe7u2.fsf@elephly.net> List-Id: Bug reports for GNU Guix List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-guix-bounces+gcggb-bug-guix=m.gmane.org@gnu.org Sender: "bug-Guix" To: Ricardo Wurmus , Ludovic =?UTF-8?Q?Court=C3=A8s?= Cc: 34135@debbugs.gnu.org Le 21 janvier 2019 09:24:53 GMT+01:00, Ricardo Wurmus a =C3=A9crit : > >Ludovic Court=C3=A8s writes: > >> Hi Julien, >> >> Julien Lepiller skribis: >> >>> Try setting security=2Esandbox=2Econtent=2Eread_path_whitelist to >/gnu/store/ >>> (with a leading /) in about:config=2E >> >> Setting it to =E2=80=9C/gnu/store/=E2=80=9D (with a trailing slash) wor= ks, thank you! >> >> It turns out that setting LIBGL_DRIVERS_PATH is even unnecessary=2E >> >> I suppose we should patch the default value of >> =E2=80=98security=2Esandbox=2Econtent=2Eread_path_whitelist=E2=80=99 in= our package=2E What >do >> people think? > >It isn=E2=80=99t much of a sandbox if all of /gnu/store would be permitte= d=2E=20 >Can >this be reduced to the paths of store items that are known at build >time? You'll have to list every library and there dependencies=2E Is that possib= le? Also I think icecat has read permission to /usr by default, so setting = permission to the store is similar=2E