aboutsummaryrefslogtreecommitdiffstats
path: root/src/firejail/firejail.h
diff options
context:
space:
mode:
authorLibravatar smitsohu <smitsohu@gmail.com>2022-07-19 15:19:24 +0200
committerLibravatar smitsohu <smitsohu@gmail.com>2022-07-23 16:21:14 +0200
commit87afef810c2dfbf67420dc76a67c707fbb7353db (patch)
treed44aed25d9c050967eb6abe31b4081c0956f4a74 /src/firejail/firejail.h
parentprotocol filter: add x32 ABI handling (diff)
downloadfirejail-87afef810c2dfbf67420dc76a67c707fbb7353db.tar.gz
firejail-87afef810c2dfbf67420dc76a67c707fbb7353db.tar.zst
firejail-87afef810c2dfbf67420dc76a67c707fbb7353db.zip
introduce new option restrict-namespaces
Diffstat (limited to 'src/firejail/firejail.h')
-rw-r--r--src/firejail/firejail.h2
1 files changed, 2 insertions, 0 deletions
diff --git a/src/firejail/firejail.h b/src/firejail/firejail.h
index f8a23678a..b744ebd45 100644
--- a/src/firejail/firejail.h
+++ b/src/firejail/firejail.h
@@ -198,6 +198,7 @@ typedef struct config_t {
198 char *seccomp_list_drop, *seccomp_list_drop32; // seccomp drop list 198 char *seccomp_list_drop, *seccomp_list_drop32; // seccomp drop list
199 char *seccomp_list_keep, *seccomp_list_keep32; // seccomp keep list 199 char *seccomp_list_keep, *seccomp_list_keep32; // seccomp keep list
200 char *protocol; // protocol list 200 char *protocol; // protocol list
201 char *restrict_namespaces; // namespaces list
201 char *seccomp_error_action; // error action: kill, log or errno 202 char *seccomp_error_action; // error action: kill, log or errno
202 203
203 // rlimits 204 // rlimits
@@ -633,6 +634,7 @@ int seccomp_load(const char *fname);
633int seccomp_filter_drop(bool native); 634int seccomp_filter_drop(bool native);
634int seccomp_filter_keep(bool native); 635int seccomp_filter_keep(bool native);
635int seccomp_filter_mdwx(bool native); 636int seccomp_filter_mdwx(bool native);
637int seccomp_filter_namespaces(bool native, const char *list);
636void seccomp_print_filter(pid_t pid) __attribute__((noreturn)); 638void seccomp_print_filter(pid_t pid) __attribute__((noreturn));
637 639
638// caps.c 640// caps.c