summaryrefslogtreecommitdiffstats
path: root/etc/firejail-default
diff options
context:
space:
mode:
authorLibravatar Vincent43 <31109921+Vincent43@users.noreply.github.com>2018-01-23 09:09:59 +0000
committerLibravatar GitHub <noreply@github.com>2018-01-23 09:09:59 +0000
commitb3d310df7f22602ab2beb2435a03aba194e650f7 (patch)
tree5ddae7ffb1651f8ee694fe5100d949a0d7c8a31f /etc/firejail-default
parentApparmor: fix kodi plugins (diff)
downloadfirejail-b3d310df7f22602ab2beb2435a03aba194e650f7.tar.gz
firejail-b3d310df7f22602ab2beb2435a03aba194e650f7.tar.zst
firejail-b3d310df7f22602ab2beb2435a03aba194e650f7.zip
Apparmor: Revert /proc changes
Diffstat (limited to 'etc/firejail-default')
-rw-r--r--etc/firejail-default32
1 files changed, 16 insertions, 16 deletions
diff --git a/etc/firejail-default b/etc/firejail-default
index b5d5a2738..e5010eaab 100644
--- a/etc/firejail-default
+++ b/etc/firejail-default
@@ -61,23 +61,23 @@ owner /{run,dev}/shm/** rmwk,
61/sys/devices/ r, 61/sys/devices/ r,
62/sys/devices/** r, 62/sys/devices/** r,
63 63
64owner /proc/@{PID}/ r, 64/proc/@{PID}/ r,
65owner /proc/@{PID}/fd/ r, 65/proc/@{PID}/fd/ r,
66owner /proc/@{PID}/task/ r, 66/proc/@{PID}/task/ r,
67owner /proc/@{PID}/cmdline r, 67/proc/@{PID}/cmdline r,
68owner /proc/@{PID}/comm r, 68/proc/@{PID}/comm r,
69owner /proc/@{PID}/stat r, 69/proc/@{PID}/stat r,
70owner /proc/@{PID}/statm r, 70/proc/@{PID}/statm r,
71owner /proc/@{PID}/status r, 71/proc/@{PID}/status r,
72owner /proc/@{PID}/task/@{PID}/stat r, 72/proc/@{PID}/task/@{PID}/stat r,
73owner /proc/@{PID}/maps r, 73/proc/@{PID}/maps r,
74owner /proc/@{PID}/mounts r, 74/proc/@{PID}/mounts r,
75owner /proc/@{PID}/mountinfo r, 75/proc/@{PID}/mountinfo r,
76owner /proc/@{PID}/oom_score_adj r, 76/proc/@{PID}/oom_score_adj r,
77owner /proc/@{PID}/auxv r, 77/proc/@{PID}/auxv r,
78/proc/@{PID}/net/dev r, 78/proc/@{PID}/net/dev r,
79owner /proc/@{PID}/loginuid r, 79/proc/@{PID}/loginuid r,
80owner /proc/@{PID}/environ r, 80/proc/@{PID}/environ r,
81 81
82########## 82##########
83# Allow running programs only from well-known system directories. If you need 83# Allow running programs only from well-known system directories. If you need