diff options
| author | Tor Hedin Brønner <torhedinbronner@gmail.com> | 2019-10-19 15:15:20 +0200 |
|---|---|---|
| committer | Tor Hedin Brønner <torhedinbronner@gmail.com> | 2019-10-19 17:07:28 +0200 |
| commit | 9742df15950a4c53e89fcc79feabd3a1a78827e2 (patch) | |
| tree | ffeef6bf94b8c097e981d8b545d0832cee801ad6 /pkgs/development/python-modules/termplotlib/gnuplot-subprocess.patch | |
| parent | c8036d1050f20b929513b2d9e7136a0ef7798c86 (diff) | |
gnome3.mutter: drop inheritable cap_sys_nice
In NixOS extra capabilities are provided through the ambient set which provides
real inheritability to user run processes [0].
We don't want gome-shell to spawn processes with cap_sys_nice however (apart
from the obvious this also breaks eg. flatpaks). So we drop inheritable when
starting to prevent further inheritance (the ambient set is only propagated
if inherit is set).
[0] https://github.com/torvalds/linux/commit/58319057b7847667f0c9585b9de0e8932b0fdb08
Diffstat (limited to 'pkgs/development/python-modules/termplotlib/gnuplot-subprocess.patch')
0 files changed, 0 insertions, 0 deletions
