aboutsummaryrefslogtreecommitdiffstats
path: root/src/bash_completion
diff options
context:
space:
mode:
authorLibravatar Kelvin M. Klann <kmk3.code@protonmail.com>2024-02-01 23:21:26 -0300
committerLibravatar Kelvin M. Klann <kmk3.code@protonmail.com>2024-02-02 19:37:06 -0300
commitf70ffbe76cd06c03442132f06d503846a415f24c (patch)
treef48b2cf278c3b60717ca9ff3b9c3dd26ab2c7ef2 /src/bash_completion
parentcrawl.profile: allow lua (#6182) (diff)
downloadfirejail-f70ffbe76cd06c03442132f06d503846a415f24c.tar.gz
firejail-f70ffbe76cd06c03442132f06d503846a415f24c.tar.zst
firejail-f70ffbe76cd06c03442132f06d503846a415f24c.zip
landlock: split .special into .makeipc and .makedev
As discussed with @topimiettinen[1], it is unlikely that an unprivileged process would need to directly create block or character devices. Also, `landlock.special` is not very descriptive of what it allows. So split `landlock.special` into: * `landlock.makeipc`: allow creating named pipes and sockets (which are usually used for inter-process communication) * `landlock.makedev`: allow creating block and character devices Misc: The `makedev` name is based on `nodev` from mount(8), which makes mount not interpret block and character devices. `ipc` was suggested by @rusty-snake[2]. Relates to #6078. [1] https://github.com/netblue30/firejail/pull/6078#pullrequestreview-1740569786 [2] https://github.com/netblue30/firejail/pull/6187#issuecomment-1924107294
Diffstat (limited to 'src/bash_completion')
-rw-r--r--src/bash_completion/firejail.bash_completion.in6
1 files changed, 5 insertions, 1 deletions
diff --git a/src/bash_completion/firejail.bash_completion.in b/src/bash_completion/firejail.bash_completion.in
index 76667ca0c..6c985bc6e 100644
--- a/src/bash_completion/firejail.bash_completion.in
+++ b/src/bash_completion/firejail.bash_completion.in
@@ -53,7 +53,11 @@ _firejail()
53 _filedir 53 _filedir
54 return 0 54 return 0
55 ;; 55 ;;
56 --landlock.special) 56 --landlock.makeipc)
57 _filedir
58 return 0
59 ;;
60 --landlock.makedev)
57 _filedir 61 _filedir
58 return 0 62 return 0
59 ;; 63 ;;