aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@protonmail.com>2021-02-21 08:54:41 -0500
committerLibravatar netblue30 <netblue30@protonmail.com>2021-02-21 08:54:41 -0500
commite43bc70f269a82b744d0df5721394be103cf68f5 (patch)
tree489f64300d57960c4492f4e60cc4afd1761f55ea
parentporting from main: mkasc.sh: fix typo of Calculating (diff)
downloadfirejail-e43bc70f269a82b744d0df5721394be103cf68f5.tar.gz
firejail-e43bc70f269a82b744d0df5721394be103cf68f5.tar.zst
firejail-e43bc70f269a82b744d0df5721394be103cf68f5.zip
porting from main: apparmor capabilities fix
-rw-r--r--etc/apparmor/firejail-default42
1 files changed, 8 insertions, 34 deletions
diff --git a/etc/apparmor/firejail-default b/etc/apparmor/firejail-default
index ec87f1d2d..80d527e41 100644
--- a/etc/apparmor/firejail-default
+++ b/etc/apparmor/firejail-default
@@ -126,40 +126,14 @@ signal (receive),
126# We let Firejail deal with capabilities, but ensure that 126# We let Firejail deal with capabilities, but ensure that
127# some AppArmor related capabilities will not be available. 127# some AppArmor related capabilities will not be available.
128########## 128##########
129capability chown, 129# The list of recognized capabilities varies from one apparmor version to another.
130capability dac_override, 130# For example on Debian 10 (apparmor 2.13.2) checkpoint_restore, perfmon, bpf are not available
131capability dac_read_search, 131# We allow all caps by default and remove the ones we don't like:
132capability fowner, 132capability,
133capability fsetid, 133deny capability audit_write,
134capability kill, 134deny capability audit_control,
135capability setgid, 135deny capability mac_override,
136capability setuid, 136deny capability mac_admin,
137capability setpcap,
138capability linux_immutable,
139capability net_bind_service,
140capability net_broadcast,
141capability net_admin,
142capability net_raw,
143capability ipc_lock,
144capability ipc_owner,
145capability sys_module,
146capability sys_rawio,
147capability sys_chroot,
148capability sys_ptrace,
149capability sys_pacct,
150capability sys_admin,
151capability sys_boot,
152capability sys_nice,
153capability sys_resource,
154capability sys_time,
155capability sys_tty_config,
156capability mknod,
157capability lease,
158#capability audit_write,
159#capability audit_control,
160capability setfcap,
161#capability mac_override,
162#capability mac_admin,
163 137
164# Site-specific additions and overrides. See local/README for details. 138# Site-specific additions and overrides. See local/README for details.
165#include <local/firejail-default> 139#include <local/firejail-default>