From 11af6e530ef421af5e6f14d9447f1d4172698327 Mon Sep 17 00:00:00 2001 From: Albert S Date: Mon, 30 May 2022 00:03:38 +0200 Subject: [PATCH] gui: sandbox: Add 'error' to vow_promises to avoid getting killed on ioctl() with TIOCSTI --- gui/main.cpp | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/gui/main.cpp b/gui/main.cpp index 2c471a4..0a1c110 100644 --- a/gui/main.cpp +++ b/gui/main.cpp @@ -45,7 +45,8 @@ void enableIpcSandbox() policy->namespace_options = EXILE_UNSHARE_NETWORK | EXILE_UNSHARE_USER; policy->no_new_privs = 1; policy->drop_caps = 1; - policy->vow_promises = exile_vows_from_str("thread cpath wpath rpath unix stdio prot_exec proc shm fsnotify ioctl"); + policy->vow_promises = + exile_vows_from_str("thread cpath wpath rpath unix stdio prot_exec proc shm fsnotify ioctl error"); QString ipcSocketPath = Common::ipcSocketPath(); QFileInfo info{ipcSocketPath};