aboutsummaryrefslogtreecommitdiffstats
path: root/install.sh
diff options
context:
space:
mode:
authorLibravatar smitsohu <smitsohu@gmail.com>2018-12-07 16:29:06 +0100
committerLibravatar smitsohu <smitsohu@gmail.com>2018-12-07 16:29:06 +0100
commitc083a7b737050c532977b46fac6400f1dbc24ff6 (patch)
tree3f9438ec7985b5191da4ca47fb0b9e4822cf249f /install.sh
parentadd HAS_NODBUS conditional, ${RUNUSER} makro (diff)
downloadfirejail-c083a7b737050c532977b46fac6400f1dbc24ff6.tar.gz
firejail-c083a7b737050c532977b46fac6400f1dbc24ff6.tar.zst
firejail-c083a7b737050c532977b46fac6400f1dbc24ff6.zip
improve sandboxing of KDE apps: set KDE_FORK_SLAVES, blacklist slave-sockets
setting the KDE_FORK_SLAVES environment variable removes all inconsistencies that arise from slaves running outside the sandbox or in a different sandbox; it also makes it slightly more difficult to abuse KIO in general and helps to mitigate security problems due to thumbnailing, which now always happens inside the same sandbox. The trade-off is more concurrently running slave processes. closes #2285
Diffstat (limited to 'install.sh')
0 files changed, 0 insertions, 0 deletions