aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar Vincent43 <31109921+Vincent43@users.noreply.github.com>2019-07-14 14:37:58 +0200
committerLibravatar Vincent43 <31109921+Vincent43@users.noreply.github.com>2019-07-14 14:37:58 +0200
commit2eca1252e3491f098f036483855e3402882ebc54 (patch)
tree25cd65849adbc5067173b9342ae1cfc5b812f494 /etc
parenthomedirs: turn "informational error" into warning (diff)
downloadfirejail-2eca1252e3491f098f036483855e3402882ebc54.tar.gz
firejail-2eca1252e3491f098f036483855e3402882ebc54.tar.zst
firejail-2eca1252e3491f098f036483855e3402882ebc54.zip
apparmor: allow writing to /proc/@{PID}/comm
This is needed by various electron apps, see: https://github.com/netblue30/firejail/issues/2538 https://github.com/netblue30/firejail/issues/2854
Diffstat (limited to 'etc')
-rw-r--r--etc/firejail-default3
-rw-r--r--etc/standardnotes-desktop.profile3
2 files changed, 4 insertions, 2 deletions
diff --git a/etc/firejail-default b/etc/firejail-default
index 02a241c34..7735f2f80 100644
--- a/etc/firejail-default
+++ b/etc/firejail-default
@@ -66,6 +66,9 @@ owner /{,var/}run/media/** w,
66# Needed for firefox sandbox 66# Needed for firefox sandbox
67/proc/[0-9]*/{uid_map,gid_map,setgroups} w, 67/proc/[0-9]*/{uid_map,gid_map,setgroups} w,
68 68
69# Needed for electron apps
70/proc/@{PID}/comm w,
71
69# Silence noise 72# Silence noise
70deny /proc/@{PID}/oom_adj w, 73deny /proc/@{PID}/oom_adj w,
71deny /proc/@{PID}/oom_score_adj w, 74deny /proc/@{PID}/oom_score_adj w,
diff --git a/etc/standardnotes-desktop.profile b/etc/standardnotes-desktop.profile
index 7b89e1add..5703f932a 100644
--- a/etc/standardnotes-desktop.profile
+++ b/etc/standardnotes-desktop.profile
@@ -21,7 +21,7 @@ whitelist ${HOME}/Standard Notes Backups
21whitelist ${HOME}/.config/Standard Notes 21whitelist ${HOME}/.config/Standard Notes
22include whitelist-var-common.inc 22include whitelist-var-common.inc
23 23
24#apparmor 24apparmor
25caps.drop all 25caps.drop all
26machine-id 26machine-id
27netfilter 27netfilter
@@ -34,7 +34,6 @@ nosound
34notv 34notv
35nou2f 35nou2f
36protocol unix,inet,inet6,netlink 36protocol unix,inet,inet6,netlink
37#seccomp
38seccomp.drop @clock,@cpu-emulation,@debug,@module,@obsolete,@raw-io,@reboot,@resources,@swap,acct,add_key,bpf,fanotify_init,io_cancel,io_destroy,io_getevents,io_setup,io_submit,ioprio_set,kcmp,keyctl,mincore,mount,name_to_handle_at,nfsservctl,ni_syscall,open_by_handle_at,pivot_root,remap_file_pages,request_key,setdomainname,sethostname,syslog,umount,umount2,userfaultfd,vhangup,vmsplice 37seccomp.drop @clock,@cpu-emulation,@debug,@module,@obsolete,@raw-io,@reboot,@resources,@swap,acct,add_key,bpf,fanotify_init,io_cancel,io_destroy,io_getevents,io_setup,io_submit,ioprio_set,kcmp,keyctl,mincore,mount,name_to_handle_at,nfsservctl,ni_syscall,open_by_handle_at,pivot_root,remap_file_pages,request_key,setdomainname,sethostname,syslog,umount,umount2,userfaultfd,vhangup,vmsplice
39 38
40disable-mnt 39disable-mnt