aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@protonmail.com>2022-02-03 09:32:25 -0500
committerLibravatar netblue30 <netblue30@protonmail.com>2022-02-03 09:32:25 -0500
commit9b22a26f767f5a7605ad8be7b93f6c21dad04eb7 (patch)
treeadce9713754db45ef15696fe8570013d2c821cf2
parentfix map view in geeqie (diff)
parentMerge pull request #4889 from kmk3/relnotes-add-security-items (diff)
downloadfirejail-9b22a26f767f5a7605ad8be7b93f6c21dad04eb7.tar.gz
firejail-9b22a26f767f5a7605ad8be7b93f6c21dad04eb7.tar.zst
firejail-9b22a26f767f5a7605ad8be7b93f6c21dad04eb7.zip
Merge branch 'master' of ssh://github.com/netblue30/firejail
-rw-r--r--RELNOTES4
-rw-r--r--etc/inc/disable-programs.inc1
-rw-r--r--etc/inc/whitelist-usr-share-common.inc1
-rw-r--r--etc/profile-m-z/steam.profile5
4 files changed, 11 insertions, 0 deletions
diff --git a/RELNOTES b/RELNOTES
index 8fd438ad3..651512831 100644
--- a/RELNOTES
+++ b/RELNOTES
@@ -1,5 +1,9 @@
1firejail (0.9.68rc2) baseline; urgency=low 1firejail (0.9.68rc2) baseline; urgency=low
2 * work in progress 2 * work in progress
3 * security: on Ubuntu, the PPA is now recommended over the distro package
4 (see README.md) (#4748)
5 * security: bugfix: private-cwd leaks access to the entire filesystem
6 (#4780); reported by Hugo Osvaldo Barrera
3 * exit code: distinguish fatal signals by adding 128 (#4533) 7 * exit code: distinguish fatal signals by adding 128 (#4533)
4 * close file descriptors greater than 2 (--keep-fd) (#4845) 8 * close file descriptors greater than 2 (--keep-fd) (#4845)
5 * intrusion detection system (--ids-init, --ids-check) 9 * intrusion detection system (--ids-init, --ids-check)
diff --git a/etc/inc/disable-programs.inc b/etc/inc/disable-programs.inc
index 5a189559a..255da0fbd 100644
--- a/etc/inc/disable-programs.inc
+++ b/etc/inc/disable-programs.inc
@@ -286,6 +286,7 @@ blacklist ${HOME}/.config/LibreCAD
286blacklist ${HOME}/.config/Loop_Hero 286blacklist ${HOME}/.config/Loop_Hero
287blacklist ${HOME}/.config/Luminance 287blacklist ${HOME}/.config/Luminance
288blacklist ${HOME}/.config/LyX 288blacklist ${HOME}/.config/LyX
289blacklist ${HOME}/.config/MangoHud
289blacklist ${HOME}/.config/Mattermost 290blacklist ${HOME}/.config/Mattermost
290blacklist ${HOME}/.config/Meltytech 291blacklist ${HOME}/.config/Meltytech
291blacklist ${HOME}/.config/Mendeley Ltd. 292blacklist ${HOME}/.config/Mendeley Ltd.
diff --git a/etc/inc/whitelist-usr-share-common.inc b/etc/inc/whitelist-usr-share-common.inc
index 0049ce804..b4e5ac5d9 100644
--- a/etc/inc/whitelist-usr-share-common.inc
+++ b/etc/inc/whitelist-usr-share-common.inc
@@ -12,6 +12,7 @@ whitelist /usr/share/cursors
12whitelist /usr/share/dconf 12whitelist /usr/share/dconf
13whitelist /usr/share/distro-info 13whitelist /usr/share/distro-info
14whitelist /usr/share/drirc.d 14whitelist /usr/share/drirc.d
15whitelist /usr/share/egl
15whitelist /usr/share/enchant 16whitelist /usr/share/enchant
16whitelist /usr/share/enchant-2 17whitelist /usr/share/enchant-2
17whitelist /usr/share/file 18whitelist /usr/share/file
diff --git a/etc/profile-m-z/steam.profile b/etc/profile-m-z/steam.profile
index b31818274..b0be8a517 100644
--- a/etc/profile-m-z/steam.profile
+++ b/etc/profile-m-z/steam.profile
@@ -8,6 +8,7 @@ include globals.local
8 8
9noblacklist ${HOME}/.config/Epic 9noblacklist ${HOME}/.config/Epic
10noblacklist ${HOME}/.config/Loop_Hero 10noblacklist ${HOME}/.config/Loop_Hero
11noblacklist ${HOME}/.config/MangoHud
11noblacklist ${HOME}/.config/ModTheSpire 12noblacklist ${HOME}/.config/ModTheSpire
12noblacklist ${HOME}/.config/RogueLegacy 13noblacklist ${HOME}/.config/RogueLegacy
13noblacklist ${HOME}/.config/RogueLegacyStorageContainer 14noblacklist ${HOME}/.config/RogueLegacyStorageContainer
@@ -55,6 +56,7 @@ include disable-programs.inc
55 56
56mkdir ${HOME}/.config/Epic 57mkdir ${HOME}/.config/Epic
57mkdir ${HOME}/.config/Loop_Hero 58mkdir ${HOME}/.config/Loop_Hero
59mkdir ${HOME}/.config/MangoHud
58mkdir ${HOME}/.config/ModTheSpire 60mkdir ${HOME}/.config/ModTheSpire
59mkdir ${HOME}/.config/RogueLegacy 61mkdir ${HOME}/.config/RogueLegacy
60mkdir ${HOME}/.config/unity3d 62mkdir ${HOME}/.config/unity3d
@@ -85,6 +87,7 @@ mkfile ${HOME}/.steampath
85mkfile ${HOME}/.steampid 87mkfile ${HOME}/.steampid
86whitelist ${HOME}/.config/Epic 88whitelist ${HOME}/.config/Epic
87whitelist ${HOME}/.config/Loop_Hero 89whitelist ${HOME}/.config/Loop_Hero
90whitelist ${HOME}/.config/MangoHud
88whitelist ${HOME}/.config/ModTheSpire 91whitelist ${HOME}/.config/ModTheSpire
89whitelist ${HOME}/.config/RogueLegacy 92whitelist ${HOME}/.config/RogueLegacy
90whitelist ${HOME}/.config/RogueLegacyStorageContainer 93whitelist ${HOME}/.config/RogueLegacyStorageContainer
@@ -162,3 +165,5 @@ private-tmp
162 165
163# dbus-user none 166# dbus-user none
164# dbus-system none 167# dbus-system none
168
169read-only ${HOME}/.config/MangoHud