aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@yahoo.com>2019-01-09 09:27:12 -0500
committerLibravatar netblue30 <netblue30@yahoo.com>2019-01-09 09:27:12 -0500
commit2aec49709bdebcf4e32d540f4e92cfe033170f12 (patch)
tree5b4e267ede8844e538425ead641e45b6cdc1b18f
parentfrom mainline: Correctly set address length in arp frames (diff)
downloadfirejail-2aec49709bdebcf4e32d540f4e92cfe033170f12.tar.gz
firejail-2aec49709bdebcf4e32d540f4e92cfe033170f12.tar.zst
firejail-2aec49709bdebcf4e32d540f4e92cfe033170f12.zip
mainline merge: fix netfilter-default functionality in /etc/firejail/firejail.config
-rw-r--r--src/firejail/netfilter.c8
-rw-r--r--status8
2 files changed, 12 insertions, 4 deletions
diff --git a/src/firejail/netfilter.c b/src/firejail/netfilter.c
index ed2d019ab..22c8392a0 100644
--- a/src/firejail/netfilter.c
+++ b/src/firejail/netfilter.c
@@ -69,8 +69,12 @@ void netfilter(const char *fname) {
69 if (set_perms(SBOX_STDIN_FILE, getuid(), getgid(), 0644)) 69 if (set_perms(SBOX_STDIN_FILE, getuid(), getgid(), 0644))
70 errExit("set_perms"); 70 errExit("set_perms");
71 71
72 if (fname == NULL) 72 if (fname == NULL) {
73 sbox_run(SBOX_USER| SBOX_CAPS_NONE | SBOX_SECCOMP, 2, PATH_FNETFILTER, SBOX_STDIN_FILE); 73 if (netfilter_default)
74 sbox_run(SBOX_USER| SBOX_CAPS_NONE | SBOX_SECCOMP, 3, PATH_FNETFILTER, netfilter_default, SBOX_STDIN_FILE);
75 else
76 sbox_run(SBOX_USER| SBOX_CAPS_NONE | SBOX_SECCOMP, 2, PATH_FNETFILTER, SBOX_STDIN_FILE);
77 }
74 else 78 else
75 sbox_run(SBOX_USER| SBOX_CAPS_NONE | SBOX_SECCOMP, 3, PATH_FNETFILTER, fname, SBOX_STDIN_FILE); 79 sbox_run(SBOX_USER| SBOX_CAPS_NONE | SBOX_SECCOMP, 3, PATH_FNETFILTER, fname, SBOX_STDIN_FILE);
76 80
diff --git a/status b/status
index 84ec18951..fb8d548b7 100644
--- a/status
+++ b/status
@@ -1,5 +1,9 @@
12019: Jan 2 1
2done: Correctly set address length in arp frames 2Jan 9: fix netfilter-default functionality in /etc/firejail/firejail.config
3Jan 8: test caps join
4Jan 8: testing seccomp/join
5Jan 8: fix join/seccomp #2296
6Jan 2: Correctly set address length in arp frames
3 7
4Nov 6: mainline merge 8Nov 6: mainline merge
5done: removed transfer.sh support from travis build 9done: removed transfer.sh support from travis build