Our sandboxed apps won't really protect users

Alexander Larsson alexl at redhat.com
Tue Sep 15 09:51:49 UTC 2015


On Mon, 2015-09-14 at 11:35 -0400, Matthias Clasen wrote:
> On Fri, 2015-09-11 at 06:07 -0500, kendell clark wrote:
> > hi
> > I've been following this thread for a while, and I've got a couple
> > of
> > questions. Will this xdg-app export to, or be able to grant access
> > to,
> > accessibility tools, such as orca? 
> 
> With the way a11y is currently set up, we will have to do a tiny
> amount of extra plumbing to make the accessibility bus available
> inside the sandbox. That is not hard at all. Unfortunately, it will
> probably give apps a way out of the sandbox, so we should look at
> ways
> to limit the access the a11y bus from inside the sandbox to just
> 'send
> events and receive commands'.
> 
> Alex, have you looked at this ?

No, i have not. Its on my todo list, but honestly its been pushed down
partially because i have no real idea how this stuff works at all. :/



More information about the desktop mailing list