aboutsummaryrefslogtreecommitdiffstats
path: root/Makefile
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@protonmail.com>2023-07-12 09:31:49 -0400
committerLibravatar netblue30 <netblue30@protonmail.com>2023-07-12 09:31:49 -0400
commit6fa19aab98b0b350c3a77c5f614f1b781760ab53 (patch)
treeab1d666b58ce79cad607324ac7869ece36ecae91 /Makefile
parentfix server.profile (diff)
downloadfirejail-6fa19aab98b0b350c3a77c5f614f1b781760ab53.tar.gz
firejail-6fa19aab98b0b350c3a77c5f614f1b781760ab53.tar.zst
firejail-6fa19aab98b0b350c3a77c5f614f1b781760ab53.zip
feature: use seccomp filters build at install time for --restrict-namespaces
Diffstat (limited to 'Makefile')
-rw-r--r--Makefile4
1 files changed, 3 insertions, 1 deletions
diff --git a/Makefile b/Makefile
index 494f853d5..1343cb87d 100644
--- a/Makefile
+++ b/Makefile
@@ -17,7 +17,7 @@ SBOX_APPS_NON_DUMPABLE += src/fnettrace-icmp/fnettrace-icmp
17MYDIRS = src/lib src/man $(COMPLETIONDIRS) 17MYDIRS = src/lib src/man $(COMPLETIONDIRS)
18MYLIBS = src/libpostexecseccomp/libpostexecseccomp.so src/libtrace/libtrace.so src/libtracelog/libtracelog.so 18MYLIBS = src/libpostexecseccomp/libpostexecseccomp.so src/libtrace/libtrace.so src/libtracelog/libtracelog.so
19COMPLETIONS = src/zsh_completion/_firejail src/bash_completion/firejail.bash_completion 19COMPLETIONS = src/zsh_completion/_firejail src/bash_completion/firejail.bash_completion
20SECCOMP_FILTERS = seccomp seccomp.debug seccomp.32 seccomp.block_secondary seccomp.mdwx seccomp.mdwx.32 20SECCOMP_FILTERS = seccomp seccomp.debug seccomp.32 seccomp.block_secondary seccomp.mdwx seccomp.mdwx.32 seccomp.namespaces seccomp.namespaces.32
21 21
22SYSCALL_HEADERS := $(sort $(wildcard src/include/syscall*.h)) 22SYSCALL_HEADERS := $(sort $(wildcard src/include/syscall*.h))
23 23
@@ -63,6 +63,8 @@ define build_filters
63 src/fseccomp/fseccomp secondary block seccomp.block_secondary 63 src/fseccomp/fseccomp secondary block seccomp.block_secondary
64 src/fseccomp/fseccomp memory-deny-write-execute seccomp.mdwx 64 src/fseccomp/fseccomp memory-deny-write-execute seccomp.mdwx
65 src/fseccomp/fseccomp memory-deny-write-execute.32 seccomp.mdwx.32 65 src/fseccomp/fseccomp memory-deny-write-execute.32 seccomp.mdwx.32
66 src/fseccomp/fseccomp restrict-namespaces seccomp.namespaces cgroup,ipc,net,mnt,pid,time,user,uts
67 src/fseccomp/fseccomp restrict-namespaces seccomp.namespaces.32 cgroup,ipc,net,mnt,pid,time,user,uts
66endef 68endef
67 69
68 70