aboutsummaryrefslogtreecommitdiffstats
path: root/etc/apparmor
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@protonmail.com>2021-02-21 08:47:45 -0500
committerLibravatar netblue30 <netblue30@protonmail.com>2021-02-21 08:47:45 -0500
commit3fbdc9f59a099b960a3a74ccd3c1c29078ecdef3 (patch)
treea1374e83f208a9029aa0447a24ea411670930390 /etc/apparmor
parentjaitest - simple sandbox testing utility program (diff)
downloadfirejail-3fbdc9f59a099b960a3a74ccd3c1c29078ecdef3.tar.gz
firejail-3fbdc9f59a099b960a3a74ccd3c1c29078ecdef3.tar.zst
firejail-3fbdc9f59a099b960a3a74ccd3c1c29078ecdef3.zip
apparmor capabilities fix
Diffstat (limited to 'etc/apparmor')
-rw-r--r--etc/apparmor/firejail-default45
1 files changed, 8 insertions, 37 deletions
diff --git a/etc/apparmor/firejail-default b/etc/apparmor/firejail-default
index 397bf753b..80d527e41 100644
--- a/etc/apparmor/firejail-default
+++ b/etc/apparmor/firejail-default
@@ -126,43 +126,14 @@ signal (receive),
126# We let Firejail deal with capabilities, but ensure that 126# We let Firejail deal with capabilities, but ensure that
127# some AppArmor related capabilities will not be available. 127# some AppArmor related capabilities will not be available.
128########## 128##########
129capability checkpoint_restore, 129# The list of recognized capabilities varies from one apparmor version to another.
130capability perfmon, 130# For example on Debian 10 (apparmor 2.13.2) checkpoint_restore, perfmon, bpf are not available
131capability bpf, 131# We allow all caps by default and remove the ones we don't like:
132capability chown, 132capability,
133capability dac_override, 133deny capability audit_write,
134capability dac_read_search, 134deny capability audit_control,
135capability fowner, 135deny capability mac_override,
136capability fsetid, 136deny capability mac_admin,
137capability kill,
138capability setgid,
139capability setuid,
140capability setpcap,
141capability linux_immutable,
142capability net_bind_service,
143capability net_broadcast,
144capability net_admin,
145capability net_raw,
146capability ipc_lock,
147capability ipc_owner,
148capability sys_module,
149capability sys_rawio,
150capability sys_chroot,
151capability sys_ptrace,
152capability sys_pacct,
153capability sys_admin,
154capability sys_boot,
155capability sys_nice,
156capability sys_resource,
157capability sys_time,
158capability sys_tty_config,
159capability mknod,
160capability lease,
161#capability audit_write,
162#capability audit_control,
163capability setfcap,
164#capability mac_override,
165#capability mac_admin,
166 137
167# Site-specific additions and overrides. See local/README for details. 138# Site-specific additions and overrides. See local/README for details.
168#include <local/firejail-default> 139#include <local/firejail-default>