From mboxrd@z Thu Jan 1 00:00:00 1970 From: Ricardo Wurmus Subject: bug#34135: IceCat lacks WebGL support Date: Mon, 21 Jan 2019 09:24:53 +0100 Message-ID: <87d0oqe7u2.fsf@elephly.net> References: <87o98cr6kx.fsf@gnu.org> <20190119180750.13c17654@lepiller.eu> <87womzlzhm.fsf@gnu.org> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Return-path: Received: from eggs.gnu.org ([209.51.188.92]:42594) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1glUuA-0002NG-Kv for bug-guix@gnu.org; Mon, 21 Jan 2019 03:26:04 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1glUu9-0005GG-W9 for bug-guix@gnu.org; Mon, 21 Jan 2019 03:26:02 -0500 Received: from debbugs.gnu.org ([209.51.188.43]:40109) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1glUu9-0005G2-Q9 for bug-guix@gnu.org; Mon, 21 Jan 2019 03:26:01 -0500 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1glUu9-0004Gv-LG for bug-guix@gnu.org; Mon, 21 Jan 2019 03:26:01 -0500 Sender: "Debbugs-submit" Resent-Message-ID: In-reply-to: <87womzlzhm.fsf@gnu.org> List-Id: Bug reports for GNU Guix List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-guix-bounces+gcggb-bug-guix=m.gmane.org@gnu.org Sender: "bug-Guix" To: Ludovic =?UTF-8?Q?Court=C3=A8s?= Cc: 34135@debbugs.gnu.org Ludovic Court=C3=A8s writes: > Hi Julien, > > Julien Lepiller skribis: > >> Try setting security.sandbox.content.read_path_whitelist to /gnu/store/ >> (with a leading /) in about:config. > > Setting it to =E2=80=9C/gnu/store/=E2=80=9D (with a trailing slash) works= , thank you! > > It turns out that setting LIBGL_DRIVERS_PATH is even unnecessary. > > I suppose we should patch the default value of > =E2=80=98security.sandbox.content.read_path_whitelist=E2=80=99 in our pac= kage. What do > people think? It isn=E2=80=99t much of a sandbox if all of /gnu/store would be permitted.= Can this be reduced to the paths of store items that are known at build time? --=20 Ricardo