aboutsummaryrefslogtreecommitdiffstats
path: root/etc/firejail-default
diff options
context:
space:
mode:
authorLibravatar smitsohu <smitsohu@gmail.com>2018-02-27 00:21:10 +0100
committerLibravatar smitsohu <smitsohu@gmail.com>2018-02-27 00:21:10 +0100
commita052d9f2be1ae0c3d4c35677312c1058c02b6bee (patch)
tree481ac54da9467f76af6d38a51bd26ca367a5781e /etc/firejail-default
parentMerge pull request #1787 from joelazar/master (diff)
downloadfirejail-a052d9f2be1ae0c3d4c35677312c1058c02b6bee.tar.gz
firejail-a052d9f2be1ae0c3d4c35677312c1058c02b6bee.tar.zst
firejail-a052d9f2be1ae0c3d4c35677312c1058c02b6bee.zip
drop cap_mac_admin in apparmor profile
Diffstat (limited to 'etc/firejail-default')
-rw-r--r--etc/firejail-default7
1 files changed, 4 insertions, 3 deletions
diff --git a/etc/firejail-default b/etc/firejail-default
index f9a876f5c..5d116fbbc 100644
--- a/etc/firejail-default
+++ b/etc/firejail-default
@@ -113,7 +113,7 @@ deny /proc/@{PID}/oom_score_adj w,
113/run/firejail/mnt/oroot/opt/** ix, 113/run/firejail/mnt/oroot/opt/** ix,
114 114
115########## 115##########
116# Allow acces to cups printing socket. 116# Allow access to cups printing socket.
117########## 117##########
118/run/cups/cups.sock w, 118/run/cups/cups.sock w,
119 119
@@ -132,7 +132,8 @@ network raw,
132signal, 132signal,
133 133
134########## 134##########
135# We let Firejail deal with capabilities. 135# We let Firejail deal with capabilities,
136# but mac_admin should be dropped in any case.
136########## 137##########
137capability chown, 138capability chown,
138capability dac_override, 139capability dac_override,
@@ -167,7 +168,7 @@ capability audit_write,
167capability audit_control, 168capability audit_control,
168capability setfcap, 169capability setfcap,
169capability mac_override, 170capability mac_override,
170capability mac_admin, 171#capability mac_admin,
171 172
172########## 173##########
173# We let Firejail deal with mount/umount functionality. 174# We let Firejail deal with mount/umount functionality.