aboutsummaryrefslogtreecommitdiffstats
path: root/etc/firejail-default
diff options
context:
space:
mode:
authorLibravatar Vincent43 <31109921+Vincent43@users.noreply.github.com>2019-07-16 14:17:41 +0200
committerLibravatar Vincent43 <31109921+Vincent43@users.noreply.github.com>2019-07-16 14:17:41 +0200
commitc9af839afddd941cb6cdb5f3d61f5bc01e513bda (patch)
treec0562737ef473395418ebe3d20bbc41169d4fede /etc/firejail-default
parentcheck for dir existence before private-* mount (diff)
downloadfirejail-c9af839afddd941cb6cdb5f3d61f5bc01e513bda.tar.gz
firejail-c9af839afddd941cb6cdb5f3d61f5bc01e513bda.tar.zst
firejail-c9af839afddd941cb6cdb5f3d61f5bc01e513bda.zip
apparmor: minor improvements
Use @{PID} consistently. Remove 'deny /proc/** w,' suggestion as it will break all whitelisted entries.
Diffstat (limited to 'etc/firejail-default')
-rw-r--r--etc/firejail-default5
1 files changed, 1 insertions, 4 deletions
diff --git a/etc/firejail-default b/etc/firejail-default
index 7735f2f80..1d3664b70 100644
--- a/etc/firejail-default
+++ b/etc/firejail-default
@@ -64,7 +64,7 @@ owner /{,var/}run/media/** w,
64/{,var/}run/cups/cups.sock w, 64/{,var/}run/cups/cups.sock w,
65 65
66# Needed for firefox sandbox 66# Needed for firefox sandbox
67/proc/[0-9]*/{uid_map,gid_map,setgroups} w, 67/proc/@{PID}/{uid_map,gid_map,setgroups} w,
68 68
69# Needed for electron apps 69# Needed for electron apps
70/proc/@{PID}/comm w, 70/proc/@{PID}/comm w,
@@ -74,9 +74,6 @@ deny /proc/@{PID}/oom_adj w,
74deny /proc/@{PID}/oom_score_adj w, 74deny /proc/@{PID}/oom_score_adj w,
75 75
76# Uncomment to silence all denied write warnings 76# Uncomment to silence all denied write warnings
77#deny /proc/** w,
78
79# Uncomment to silence all denied write warnings
80#deny /sys/** w, 77#deny /sys/** w,
81 78
82########## 79##########