summaryrefslogtreecommitdiffstats
path: root/README.md
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@yahoo.com>2018-03-16 11:00:08 -0400
committerLibravatar netblue30 <netblue30@yahoo.com>2018-03-16 11:00:08 -0400
commit971c62aa569d9161190705a0012b9ad02546822c (patch)
treef4f80dc06669568acf00f3269f765fa3150ded5c /README.md
parentAdd a LibreOffice profile alias for Base (diff)
downloadfirejail-971c62aa569d9161190705a0012b9ad02546822c.tar.gz
firejail-971c62aa569d9161190705a0012b9ad02546822c.tar.zst
firejail-971c62aa569d9161190705a0012b9ad02546822c.zip
apparmor deployment
Diffstat (limited to 'README.md')
-rw-r--r--README.md16
1 files changed, 9 insertions, 7 deletions
diff --git a/README.md b/README.md
index 906ff8481..e78c86709 100644
--- a/README.md
+++ b/README.md
@@ -207,13 +207,15 @@ AppArmor features are supported on overlayfs and chroot sandboxes.
207 207
208We are in the process of streamlining our AppArmor profile. The restrictions for /proc, /sys 208We are in the process of streamlining our AppArmor profile. The restrictions for /proc, /sys
209and /run/user directories were moved out of the profile into firejail executable. 209and /run/user directories were moved out of the profile into firejail executable.
210 210We are also adding a "apparmor yes/no" flag in /etc/firejail/firejail.config file allows the user to
211We intend to start apparmor by default for browsers, torrent clients and media players. 211enable/disable apparmor functionality globally. By default the flag is enabled.
212So far we cover Firefox (firefox-common.profile), Chromium (chromium-common.profile), 212
213transmission-qt, transmission-gtk, vlc and mpv. 213AppArmor deployment: we are starting apparmor by default for the following programs:
214 214- web browsers: firefox (firefox-common.profile), chromium (chromium-common.profile)
215"apparmor yes/no" flag in /etc/firejail/firejail.config file allows the user to enable/disable apparmor functionality globally 215- torrent clients: transmission-qt, transmission-gtk, qbittorrent
216By default the flag is enabled. 216- media players: vlc, mpv, audacious, totem, rhythmbox
217- media editing: kdenlive, audacity, handbrake, gimp, inkscape, krita, openshot
218- etc.: atril, gnome-calculator, galculator, eom, eog
217 219
218Checking apparmor status: 220Checking apparmor status:
219````` 221`````