#opensnitch firewall seems to work fine with #guix. Just had to:

One issue is that, by default, the program creates rules from full paths to executables, which is often /gnu/store/ on #guix… Which means such rules would have to be recreated after each package update.

The rules support regexes, but using that would require more configuration effort.

And is there a point in a firewall if I have to allow every request from #emacs? I suppose I could block the telemetry from the few proprietary apps I have left.

…oops, the UI just SIGSEGV’ed. Maybe not quite fine.


