aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@protonmail.com>2021-11-11 02:22:02 +0000
committerLibravatar GitHub <noreply@github.com>2021-11-11 02:22:02 +0000
commitfbad5a533b7ee9567858b1b6a4ce570d3096cc50 (patch)
treecb27800b841b81736d47b9d9a3f4f362ac5b1f64
parentdisable-common.inc: fix ssh (diff)
parentchange Fedora ssh fix (diff)
downloadfirejail-fbad5a533b7ee9567858b1b6a4ce570d3096cc50.tar.gz
firejail-fbad5a533b7ee9567858b1b6a4ce570d3096cc50.tar.zst
firejail-fbad5a533b7ee9567858b1b6a4ce570d3096cc50.zip
Merge pull request #4675 from glitsj16/ssh-fixes
more ssh fixes
-rw-r--r--etc/inc/allow-ssh.inc9
-rw-r--r--etc/inc/disable-common.inc4
2 files changed, 10 insertions, 3 deletions
diff --git a/etc/inc/allow-ssh.inc b/etc/inc/allow-ssh.inc
index a78798a18..5d41e6607 100644
--- a/etc/inc/allow-ssh.inc
+++ b/etc/inc/allow-ssh.inc
@@ -5,6 +5,11 @@ include allow-ssh.local
5noblacklist ${HOME}/.ssh 5noblacklist ${HOME}/.ssh
6noblacklist /etc/ssh 6noblacklist /etc/ssh
7noblacklist /etc/ssh/ssh_config 7noblacklist /etc/ssh/ssh_config
8noblacklist /tmp/ssh-*
9noblacklist ${PATH}/ssh 8noblacklist ${PATH}/ssh
10noblacklist /usr/lib/openssh/ssh-keysign 9noblacklist /tmp/ssh-*
10# Arch Linux and derivatives
11noblacklist /usr/lib/ssh
12# Debian/Ubuntu and derivatives
13noblacklist /usr/lib/openssh
14# Fedora and derivatives
15noblacklist /usr/libexec/openssh
diff --git a/etc/inc/disable-common.inc b/etc/inc/disable-common.inc
index 1a4de9b26..bdc5ff6b2 100644
--- a/etc/inc/disable-common.inc
+++ b/etc/inc/disable-common.inc
@@ -495,7 +495,9 @@ blacklist ${PATH}/xev
495blacklist ${PATH}/xinput 495blacklist ${PATH}/xinput
496# from 0.9.67 496# from 0.9.67
497blacklist ${PATH}/ssh 497blacklist ${PATH}/ssh
498blacklist /usr/lib/openssh/ssh-keysign 498blacklist /usr/lib/openssh
499blacklist /usr/lib/ssh
500blacklist /usr/libexec/openssh
499blacklist ${PATH}/passwd 501blacklist ${PATH}/passwd
500blacklist /usr/lib/xorg/Xorg.wrap 502blacklist /usr/lib/xorg/Xorg.wrap
501blacklist /usr/lib/policykit-1/polkit-agent-helper-1 503blacklist /usr/lib/policykit-1/polkit-agent-helper-1