aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@yahoo.com>2017-10-04 08:44:52 -0400
committerLibravatar netblue30 <netblue30@yahoo.com>2017-10-04 08:44:52 -0400
commitf61820a0a16c5751c96cff154e12d3cfe374ba99 (patch)
tree0bcfa62e2ecbdad3dc03959993090c977f5af26d
parentwhitelist /var (diff)
downloadfirejail-f61820a0a16c5751c96cff154e12d3cfe374ba99.tar.gz
firejail-f61820a0a16c5751c96cff154e12d3cfe374ba99.tar.zst
firejail-f61820a0a16c5751c96cff154e12d3cfe374ba99.zip
removed lxterminal support, blacklisting the terminal in disable-common.inc
-rw-r--r--etc/disable-common.inc1
-rw-r--r--etc/lxterminal.profile19
2 files changed, 1 insertions, 19 deletions
diff --git a/etc/disable-common.inc b/etc/disable-common.inc
index d943950d4..021e6349e 100644
--- a/etc/disable-common.inc
+++ b/etc/disable-common.inc
@@ -290,6 +290,7 @@ blacklist /tmp/.lxterminal-socket*
290blacklist /tmp/tmux-* 290blacklist /tmp/tmux-*
291 291
292# disable terminals running as server resulting in sandbox escape 292# disable terminals running as server resulting in sandbox escape
293blacklist ${PATH}/lxterminal
293blacklist ${PATH}/gnome-terminal 294blacklist ${PATH}/gnome-terminal
294blacklist ${PATH}/gnome-terminal.wrapper 295blacklist ${PATH}/gnome-terminal.wrapper
295blacklist ${PATH}/lilyterm 296blacklist ${PATH}/lilyterm
diff --git a/etc/lxterminal.profile b/etc/lxterminal.profile
deleted file mode 100644
index dbbd1ace0..000000000
--- a/etc/lxterminal.profile
+++ /dev/null
@@ -1,19 +0,0 @@
1# Firejail profile for lxterminal
2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/lxterminal.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7
8
9include /etc/firejail/disable-common.inc
10include /etc/firejail/disable-passwdmgr.inc
11include /etc/firejail/disable-programs.inc
12
13caps.drop all
14netfilter
15# noroot - somehow this breaks on Debian Jessie!
16nodvd
17notv
18protocol unix,inet,inet6
19seccomp