aboutsummaryrefslogtreecommitdiffstats
path: root/etc/cpio.profile
diff options
context:
space:
mode:
authorLibravatar smitsohu <smitsohu@gmail.com>2019-06-18 18:52:18 +0200
committerLibravatar smitsohu <smitsohu@gmail.com>2019-06-18 18:52:18 +0200
commitb59225f5d987d0467c659b0b5c0630009d519e98 (patch)
tree35f672dda1ceb649c0689c9c069a021156d8c4c9 /etc/cpio.profile
parentfix logical OR in disable_file (diff)
downloadfirejail-b59225f5d987d0467c659b0b5c0630009d519e98.tar.gz
firejail-b59225f5d987d0467c659b0b5c0630009d519e98.tar.zst
firejail-b59225f5d987d0467c659b0b5c0630009d519e98.zip
use 'x11 none' option
... instead of just blacklisting the X11 socket. Systematically added to all profiles with 'net none' and 'blacklist /tmp/.X11-unix', and a few more
Diffstat (limited to 'etc/cpio.profile')
-rw-r--r--etc/cpio.profile3
1 files changed, 1 insertions, 2 deletions
diff --git a/etc/cpio.profile b/etc/cpio.profile
index 0bb45f5cd..17a765700 100644
--- a/etc/cpio.profile
+++ b/etc/cpio.profile
@@ -10,8 +10,6 @@ include globals.local
10noblacklist /sbin 10noblacklist /sbin
11noblacklist /usr/sbin 11noblacklist /usr/sbin
12 12
13blacklist /tmp/.X11-unix
14
15include disable-common.inc 13include disable-common.inc
16# include disable-devel.inc 14# include disable-devel.inc
17include disable-exec.inc 15include disable-exec.inc
@@ -36,6 +34,7 @@ novideo
36seccomp 34seccomp
37shell none 35shell none
38tracelog 36tracelog
37x11 none
39 38
40private-cache 39private-cache
41private-dev 40private-dev