programs: mepo: sandbox

This commit is contained in:
Colin 2024-02-17 15:08:21 +00:00
parent a1470956a5
commit 2efa6d1e27

View File

@ -4,6 +4,13 @@
{
sane.programs.mepo = {
sandbox.method = "bwrap";
sandbox.wrapperType = "wrappedDerivation";
sandbox.net = "all"; # for tiles *and* for localhost comm to gpsd
sandbox.whitelistDri = true;
sandbox.whitelistWayland = true;
sandbox.whitelistDbus = [ "user" ]; # for geoclue
persist.byStore.plaintext = [ ".cache/mepo/tiles" ];
# ~/.cache/mepo/savestate has precise coordinates and pins: keep those private
persist.byStore.private = [