aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@yahoo.com>2017-09-25 09:12:37 -0400
committerLibravatar netblue30 <netblue30@yahoo.com>2017-09-25 09:12:37 -0400
commit94bb78856bb3f953fc79684622a28552d02b9d11 (patch)
treee1be67e8a345af8bc233bbaf7e9eb2e62477302e /etc
parentdisable DBus activation in firecfg (diff)
downloadfirejail-94bb78856bb3f953fc79684622a28552d02b9d11.tar.gz
firejail-94bb78856bb3f953fc79684622a28552d02b9d11.tar.zst
firejail-94bb78856bb3f953fc79684622a28552d02b9d11.zip
fix nginx and apache2, possible fix for #1534
Diffstat (limited to 'etc')
-rw-r--r--etc/disable-common.inc3
-rw-r--r--etc/server.profile3
2 files changed, 4 insertions, 2 deletions
diff --git a/etc/disable-common.inc b/etc/disable-common.inc
index abce0fe57..d943950d4 100644
--- a/etc/disable-common.inc
+++ b/etc/disable-common.inc
@@ -120,7 +120,8 @@ blacklist /var/lib/mysql/mysql.sock
120blacklist /var/lib/mysqld/mysql.sock 120blacklist /var/lib/mysqld/mysql.sock
121blacklist /var/lib/pacman 121blacklist /var/lib/pacman
122blacklist /var/lib/upower 122blacklist /var/lib/upower
123blacklist /var/log 123# blacklist /var/log - a virtual /var/log directory (mostly empty) is buid up by default for
124# every sandbox, unless --writeble-var-log switch is activated
124blacklist /var/mail 125blacklist /var/mail
125blacklist /var/opt 126blacklist /var/opt
126blacklist /var/run/acpid.socket 127blacklist /var/run/acpid.socket
diff --git a/etc/server.profile b/etc/server.profile
index edd4666e1..860e0056d 100644
--- a/etc/server.profile
+++ b/etc/server.profile
@@ -13,7 +13,6 @@ blacklist /tmp/.X11-unix
13 13
14noblacklist /sbin 14noblacklist /sbin
15noblacklist /usr/sbin 15noblacklist /usr/sbin
16# noblacklist /var/log
17# noblacklist /var/opt 16# noblacklist /var/opt
18 17
19include /etc/firejail/disable-common.inc 18include /etc/firejail/disable-common.inc
@@ -29,6 +28,8 @@ notv
29novideo 28novideo
30seccomp 29seccomp
31 30
31# netfilter /etc/firejail/webserver.net
32
32# disable-mnt 33# disable-mnt
33private 34private
34# private-bin program 35# private-bin program