aboutsummaryrefslogtreecommitdiffstats
path: root/src/firejail/seccomp.c
diff options
context:
space:
mode:
authorLibravatar Aleksey Manevich <manevich.aleksey@gmail.com>2016-08-25 01:01:06 +0300
committerLibravatar Aleksey Manevich <manevich.aleksey@gmail.com>2016-08-25 01:05:40 +0300
commit51d69322896d0f622d77dc581c35876c1c937596 (patch)
tree88bf6dd701767267ac564c008335e728a9ab727d /src/firejail/seccomp.c
parenttighten security (diff)
downloadfirejail-51d69322896d0f622d77dc581c35876c1c937596.tar.gz
firejail-51d69322896d0f622d77dc581c35876c1c937596.tar.zst
firejail-51d69322896d0f622d77dc581c35876c1c937596.zip
tighten security
Diffstat (limited to 'src/firejail/seccomp.c')
-rw-r--r--src/firejail/seccomp.c3
1 files changed, 1 insertions, 2 deletions
diff --git a/src/firejail/seccomp.c b/src/firejail/seccomp.c
index 7aaf1a5cd..c2da1168a 100644
--- a/src/firejail/seccomp.c
+++ b/src/firejail/seccomp.c
@@ -290,9 +290,8 @@ static void write_seccomp_file(void) {
290 fprintf(stderr, "Error: cannot save seccomp filter\n"); 290 fprintf(stderr, "Error: cannot save seccomp filter\n");
291 exit(1); 291 exit(1);
292 } 292 }
293 SET_PERMS_FD(fd, 0, 0, S_IRUSR | S_IWUSR);
293 close(fd); 294 close(fd);
294 if (chown(RUN_SECCOMP_CFG, 0, 0) < 0)
295 errExit("chown");
296} 295}
297 296
298// read seccomp filter from /run/firejail/mnt/seccomp 297// read seccomp filter from /run/firejail/mnt/seccomp