aboutsummaryrefslogtreecommitdiffstats
path: root/src/man/firejail.txt
diff options
context:
space:
mode:
authorLibravatar Jeff Squyres <jsquyres@cisco.com>2021-04-15 11:25:08 -0700
committerLibravatar Jeff Squyres <jsquyres@cisco.com>2021-04-20 09:41:26 -0700
commit9e95a38fe1e96a5d4b9f2e79e65a689655f255b9 (patch)
treeaf0785bdec7c40dcd15edd7eeb70a00e38cc97ed /src/man/firejail.txt
parentprofile fixes (diff)
downloadfirejail-9e95a38fe1e96a5d4b9f2e79e65a689655f255b9.tar.gz
firejail-9e95a38fe1e96a5d4b9f2e79e65a689655f255b9.tar.zst
firejail-9e95a38fe1e96a5d4b9f2e79e65a689655f255b9.zip
man: corrections regarding --private-FOO options
Commit 0.9.60-1070-g40d3604f updated the man pages with respect to --private-opt, --private-etc, and --private-srv. It was made after testing firejail 0.9.52 (from Ubuntu 18.04). However, it unfortunately did not accurately reflect the the behavior of the current HEAD at the time, because commit 0.9.56-rc1-14-ga9242301 had previously slightly changed the behavior of these three options (after 0.9.52), and was released in 0.9.56. The man pages changes made in commit 40d3604f were therefore not entirely correct. This commit updates the man pages to describe the behavior as implemented in a9242301 (and is still the behavior as of the current HEAD: 0.9.64-737-g937815ba). Signed-off-by: Jeff Squyres <jsquyres@cisco.com>
Diffstat (limited to 'src/man/firejail.txt')
-rw-r--r--src/man/firejail.txt14
1 files changed, 10 insertions, 4 deletions
diff --git a/src/man/firejail.txt b/src/man/firejail.txt
index f27379a2d..1ee7ab1f1 100644
--- a/src/man/firejail.txt
+++ b/src/man/firejail.txt
@@ -1883,7 +1883,9 @@ $
1883Build a new /etc in a temporary 1883Build a new /etc in a temporary
1884filesystem, and copy the files and directories in the list. 1884filesystem, and copy the files and directories in the list.
1885The files and directories in the list must be expressed as relative to 1885The files and directories in the list must be expressed as relative to
1886the /etc directory. 1886the /etc directory, and must not contain the / character
1887(e.g., /etc/foo must be expressed as foo, but /etc/foo/bar --
1888expressed as foo/bar -- is disallowed).
1887If no listed file is found, /etc directory will be empty. 1889If no listed file is found, /etc directory will be empty.
1888All modifications are discarded when the sandbox is closed. 1890All modifications are discarded when the sandbox is closed.
1889.br 1891.br
@@ -1893,7 +1895,7 @@ Example:
1893.br 1895.br
1894$ firejail --private-etc=group,hostname,localtime, \\ 1896$ firejail --private-etc=group,hostname,localtime, \\
1895.br 1897.br
1896nsswitch.conf,passwd,resolv.conf,default/motd-news 1898nsswitch.conf,passwd,resolv.conf
1897#ifdef HAVE_PRIVATE_HOME 1899#ifdef HAVE_PRIVATE_HOME
1898.TP 1900.TP
1899\fB\-\-private-home=file,directory 1901\fB\-\-private-home=file,directory
@@ -1968,7 +1970,9 @@ $
1968Build a new /opt in a temporary 1970Build a new /opt in a temporary
1969filesystem, and copy the files and directories in the list. 1971filesystem, and copy the files and directories in the list.
1970The files and directories in the list must be expressed as relative to 1972The files and directories in the list must be expressed as relative to
1971the /opt directory. 1973the /opt directory, and must not contain the / character
1974(e.g., /opt/foo must be expressed as foo, but /opt/foo/bar --
1975expressed as foo/bar -- is disallowed).
1972If no listed file is found, /opt directory will be empty. 1976If no listed file is found, /opt directory will be empty.
1973All modifications are discarded when the sandbox is closed. 1977All modifications are discarded when the sandbox is closed.
1974.br 1978.br
@@ -1983,7 +1987,9 @@ $ firejail --private-opt=firefox /opt/firefox/firefox
1983Build a new /srv in a temporary 1987Build a new /srv in a temporary
1984filesystem, and copy the files and directories in the list. 1988filesystem, and copy the files and directories in the list.
1985The files and directories in the list must be expressed as relative to 1989The files and directories in the list must be expressed as relative to
1986the /srv directory. 1990the /srv directory, and must not contain the / character
1991(e.g., /opt/srv must be expressed as foo, but /srv/foo/bar --
1992expressed as srv/bar -- is disallowed).
1987If no listed file is found, /srv directory will be empty. 1993If no listed file is found, /srv directory will be empty.
1988All modifications are discarded when the sandbox is closed. 1994All modifications are discarded when the sandbox is closed.
1989.br 1995.br