aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar Kelvin <kmk3.code@protonmail.com>2020-12-20 00:03:33 +0000
committerLibravatar GitHub <noreply@github.com>2020-12-20 00:03:33 +0000
commit508dc3ae991e6f0418eaf42babaf5de6db4f7cd9 (patch)
tree7db2bc3a58e13eaae3e4df294abf0888ed3f8c8b
parentarchivers: limiting file system access (#3834) (diff)
downloadfirejail-508dc3ae991e6f0418eaf42babaf5de6db4f7cd9.tar.gz
firejail-508dc3ae991e6f0418eaf42babaf5de6db4f7cd9.tar.zst
firejail-508dc3ae991e6f0418eaf42babaf5de6db4f7cd9.zip
disable-common.inc: add missing dns tools (#3828)
Add the missing binaries in the DNS section, as suggested by @glitsj16: https://github.com/netblue30/firejail/pull/3810#issuecomment-742920539 Packages and their relevant binaries: * bind: dnssec-* * knot: khost * unbound: unbound-host
-rw-r--r--etc/inc/disable-common.inc3
1 files changed, 3 insertions, 0 deletions
diff --git a/etc/inc/disable-common.inc b/etc/inc/disable-common.inc
index 2b56bb5be..d88506d90 100644
--- a/etc/inc/disable-common.inc
+++ b/etc/inc/disable-common.inc
@@ -517,16 +517,19 @@ blacklist /proc/config.gz
517blacklist ${PATH}/dig 517blacklist ${PATH}/dig
518blacklist ${PATH}/dlint 518blacklist ${PATH}/dlint
519blacklist ${PATH}/dns2tcp 519blacklist ${PATH}/dns2tcp
520blacklist ${PATH}/dnssec-*
520blacklist ${PATH}/dnswalk 521blacklist ${PATH}/dnswalk
521blacklist ${PATH}/drill 522blacklist ${PATH}/drill
522blacklist ${PATH}/host 523blacklist ${PATH}/host
523blacklist ${PATH}/iodine 524blacklist ${PATH}/iodine
524blacklist ${PATH}/kdig 525blacklist ${PATH}/kdig
526blacklist ${PATH}/khost
525blacklist ${PATH}/knsupdate 527blacklist ${PATH}/knsupdate
526blacklist ${PATH}/ldns-* 528blacklist ${PATH}/ldns-*
527blacklist ${PATH}/ldnsd 529blacklist ${PATH}/ldnsd
528blacklist ${PATH}/nslookup 530blacklist ${PATH}/nslookup
529blacklist ${PATH}/resolvectl 531blacklist ${PATH}/resolvectl
532blacklist ${PATH}/unbound-host
530 533
531# rest of ${RUNUSER} 534# rest of ${RUNUSER}
532blacklist ${RUNUSER}/*.lock 535blacklist ${RUNUSER}/*.lock