aboutsummaryrefslogtreecommitdiffstats
path: root/etc/profile-a-l/dropbox.profile
diff options
context:
space:
mode:
authorLibravatar Kelvin M. Klann <kmk3.code@protonmail.com>2024-03-24 06:44:22 +0000
committerLibravatar GitHub <noreply@github.com>2024-03-24 06:44:22 +0000
commit945ad858ed61f71b6eed852f118c292fda8442f9 (patch)
tree6b5bf13955fc3964a12eb5104936c2f05ad5c8a8 /etc/profile-a-l/dropbox.profile
parentgconf-editor: remove X11 socket blacklist (diff)
downloadfirejail-945ad858ed61f71b6eed852f118c292fda8442f9.tar.gz
firejail-945ad858ed61f71b6eed852f118c292fda8442f9.tar.zst
firejail-945ad858ed61f71b6eed852f118c292fda8442f9.zip
profiles: deny access to ~/.config/autostart (#6257)
The files in this directory are intended to be automatically executed when the user logs in. In which case, granting write access to this directory allows the program to easily escape the sandbox (by autostarting itself outside of firejail, for example). Misc: This was noticed on #6244.
Diffstat (limited to 'etc/profile-a-l/dropbox.profile')
-rw-r--r--etc/profile-a-l/dropbox.profile9
1 files changed, 6 insertions, 3 deletions
diff --git a/etc/profile-a-l/dropbox.profile b/etc/profile-a-l/dropbox.profile
index 4fdf1bbfe..3094495d6 100644
--- a/etc/profile-a-l/dropbox.profile
+++ b/etc/profile-a-l/dropbox.profile
@@ -5,7 +5,12 @@ include dropbox.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.config/autostart 8# To allow the program to autostart, add the following to dropbox.local:
9# Warning: This allows the program to easily escape the sandbox.
10#noblacklist ${HOME}/.config/autostart
11#mkfile ${HOME}/.config/autostart/dropbox.desktop
12#whitelist ${HOME}/.config/autostart/dropbox.desktop
13
9noblacklist ${HOME}/.dropbox 14noblacklist ${HOME}/.dropbox
10noblacklist ${HOME}/.dropbox-dist 15noblacklist ${HOME}/.dropbox-dist
11 16
@@ -20,8 +25,6 @@ include disable-programs.inc
20mkdir ${HOME}/.dropbox 25mkdir ${HOME}/.dropbox
21mkdir ${HOME}/.dropbox-dist 26mkdir ${HOME}/.dropbox-dist
22mkdir ${HOME}/Dropbox 27mkdir ${HOME}/Dropbox
23mkfile ${HOME}/.config/autostart/dropbox.desktop
24whitelist ${HOME}/.config/autostart/dropbox.desktop
25whitelist ${HOME}/.dropbox 28whitelist ${HOME}/.dropbox
26whitelist ${HOME}/.dropbox-dist 29whitelist ${HOME}/.dropbox-dist
27whitelist ${HOME}/Dropbox 30whitelist ${HOME}/Dropbox