On Thu, Jun 16, 2016 at 08:55:16PM +0200, Alexander Larsson wrote:
> Also, I'd like to point out that flatpak isn't always open wrt
> sandboxing even now. Its possible to grant an app filesystem access,
> and many currently do, but its also possible to run e.g. games without
> filesystem access, and we do sandbox a lot of other things (pid
> namespace, uid namespace, network access, filtered dbus access, seccomp
> filtering, etc). Its just not currently realisting to not grant some
> kind of filesystem access for apps that read user files until we finish
> the work on the file selector portal.

Cool, thanks.

-- 
Matthew Miller
<mat...@fedoraproject.org>
Fedora Project Leader
--
devel mailing list
devel@lists.fedoraproject.org
https://lists.fedoraproject.org/admin/lists/devel@lists.fedoraproject.org

Reply via email to