aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar startx2017 <vradu.startx@yandex.com>2018-09-08 07:41:49 -0400
committerLibravatar startx2017 <vradu.startx@yandex.com>2018-09-08 07:41:49 -0400
commitcba8e360e86de45405287ab1fd27850b48a125e8 (patch)
tree327ad6f5bfe757892a98e21395a0375672dfbc05 /etc
parentfinal cleanup (diff)
downloadfirejail-cba8e360e86de45405287ab1fd27850b48a125e8.tar.gz
firejail-cba8e360e86de45405287ab1fd27850b48a125e8.tar.zst
firejail-cba8e360e86de45405287ab1fd27850b48a125e8.zip
mainline merge
Diffstat (limited to 'etc')
-rw-r--r--etc/disable-devel.inc3
-rw-r--r--etc/start-tor-browser.profile2
-rw-r--r--etc/torbrowser-launcher.profile2
3 files changed, 4 insertions, 3 deletions
diff --git a/etc/disable-devel.inc b/etc/disable-devel.inc
index 0327e717e..627856803 100644
--- a/etc/disable-devel.inc
+++ b/etc/disable-devel.inc
@@ -26,7 +26,8 @@ blacklist /usr/include
26blacklist ${PATH}/clang* 26blacklist ${PATH}/clang*
27blacklist ${PATH}/lldb* 27blacklist ${PATH}/lldb*
28blacklist ${PATH}/llvm* 28blacklist ${PATH}/llvm*
29blacklist /usr/lib/llvm* 29# see issue #2106 - it disables hardware acceleration in Firefox on Radeon GPU
30# blacklist /usr/lib/llvm*
30 31
31# tcc - Tiny C Compiler 32# tcc - Tiny C Compiler
32blacklist ${PATH}/tcc 33blacklist ${PATH}/tcc
diff --git a/etc/start-tor-browser.profile b/etc/start-tor-browser.profile
index 6069c5174..4d9ebcb2e 100644
--- a/etc/start-tor-browser.profile
+++ b/etc/start-tor-browser.profile
@@ -28,7 +28,7 @@ protocol unix,inet,inet6
28seccomp.drop @clock,@cpu-emulation,@debug,@module,@obsolete,@raw-io,@reboot,@resources,@swap,acct,add_key,bpf,fanotify_init,io_cancel,io_destroy,io_getevents,io_setup,io_submit,ioprio_set,kcmp,keyctl,mount,name_to_handle_at,nfsservctl,ni_syscall,open_by_handle_at,personality,pivot_root,process_vm_readv,ptrace,remap_file_pages,request_key,setdomainname,sethostname,syslog,umount,umount2,userfaultfd,vhangup,vmsplice 28seccomp.drop @clock,@cpu-emulation,@debug,@module,@obsolete,@raw-io,@reboot,@resources,@swap,acct,add_key,bpf,fanotify_init,io_cancel,io_destroy,io_getevents,io_setup,io_submit,ioprio_set,kcmp,keyctl,mount,name_to_handle_at,nfsservctl,ni_syscall,open_by_handle_at,personality,pivot_root,process_vm_readv,ptrace,remap_file_pages,request_key,setdomainname,sethostname,syslog,umount,umount2,userfaultfd,vhangup,vmsplice
29shell none 29shell none
30# tracelog may cause issues, see github issue #1930 30# tracelog may cause issues, see github issue #1930
31tracelog 31#tracelog
32 32
33disable-mnt 33disable-mnt
34private-bin bash,sh,grep,tail,env,gpg,id,readlink,dirname,test,mkdir,ln,sed,cp,rm,getconf 34private-bin bash,sh,grep,tail,env,gpg,id,readlink,dirname,test,mkdir,ln,sed,cp,rm,getconf
diff --git a/etc/torbrowser-launcher.profile b/etc/torbrowser-launcher.profile
index f175b6590..307377acc 100644
--- a/etc/torbrowser-launcher.profile
+++ b/etc/torbrowser-launcher.profile
@@ -43,7 +43,7 @@ protocol unix,inet,inet6
43seccomp.drop @clock,@cpu-emulation,@debug,@module,@obsolete,@raw-io,@reboot,@resources,@swap,acct,add_key,bpf,fanotify_init,io_cancel,io_destroy,io_getevents,io_setup,io_submit,ioprio_set,kcmp,keyctl,mount,name_to_handle_at,nfsservctl,ni_syscall,open_by_handle_at,personality,pivot_root,process_vm_readv,ptrace,remap_file_pages,request_key,setdomainname,sethostname,syslog,umount,umount2,userfaultfd,vhangup,vmsplice 43seccomp.drop @clock,@cpu-emulation,@debug,@module,@obsolete,@raw-io,@reboot,@resources,@swap,acct,add_key,bpf,fanotify_init,io_cancel,io_destroy,io_getevents,io_setup,io_submit,ioprio_set,kcmp,keyctl,mount,name_to_handle_at,nfsservctl,ni_syscall,open_by_handle_at,personality,pivot_root,process_vm_readv,ptrace,remap_file_pages,request_key,setdomainname,sethostname,syslog,umount,umount2,userfaultfd,vhangup,vmsplice
44shell none 44shell none
45# tracelog may cause issues, see github issue #1930 45# tracelog may cause issues, see github issue #1930
46tracelog 46#tracelog
47 47
48disable-mnt 48disable-mnt
49private-bin bash,cp,dirname,env,expr,file,getconf,gpg,grep,id,ln,mkdir,python*,readlink,rm,sed,sh,tail,tar,tclsh,test,tor-browser-en,torbrowser-launcher,xz 49private-bin bash,cp,dirname,env,expr,file,getconf,gpg,grep,id,ln,mkdir,python*,readlink,rm,sed,sh,tail,tar,tclsh,test,tor-browser-en,torbrowser-launcher,xz