summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--etc/pidgin.profile5
-rw-r--r--src/firejail/dbus.c5
-rw-r--r--src/firejail/firejail.h2
-rw-r--r--src/firejail/fs.c4
-rw-r--r--src/firejail/fs_home.c6
-rw-r--r--src/firejail/fs_whitelist.c6
-rw-r--r--src/firejail/mountinfo.c4
-rw-r--r--src/firejail/pulseaudio.c4
-rw-r--r--src/firejail/sandbox.c2
-rw-r--r--src/firejail/util.c4
-rw-r--r--src/firejail/x11.c4
-rw-r--r--src/man/firejail.txt8
12 files changed, 44 insertions, 10 deletions
diff --git a/etc/pidgin.profile b/etc/pidgin.profile
index 444478149..bdd5404f5 100644
--- a/etc/pidgin.profile
+++ b/etc/pidgin.profile
@@ -6,9 +6,7 @@ include pidgin.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9mkdir ${HOME}/.purple
10noblacklist ${HOME}/.purple 9noblacklist ${HOME}/.purple
11whitelist ${HOME}/.purple
12 10
13ignore noexec ${RUNUSER} 11ignore noexec ${RUNUSER}
14ignore noexec /dev/shm 12ignore noexec /dev/shm
@@ -20,6 +18,9 @@ include disable-interpreters.inc
20include disable-passwdmgr.inc 18include disable-passwdmgr.inc
21include disable-programs.inc 19include disable-programs.inc
22include disable-xdg.inc 20include disable-xdg.inc
21
22mkdir ${HOME}/.purple
23whitelist ${HOME}/.purple
23include whitelist-common.inc 24include whitelist-common.inc
24include whitelist-var-common.inc 25include whitelist-var-common.inc
25 26
diff --git a/src/firejail/dbus.c b/src/firejail/dbus.c
index baa41e85e..b046b3279 100644
--- a/src/firejail/dbus.c
+++ b/src/firejail/dbus.c
@@ -19,7 +19,7 @@
19*/ 19*/
20#include "firejail.h" 20#include "firejail.h"
21 21
22void dbus_session_disable(void) { 22void dbus_disable(void) {
23 if (!checkcfg(CFG_DBUS)) { 23 if (!checkcfg(CFG_DBUS)) {
24 fwarning("D-Bus handling is disabled in Firejail configuration file\n"); 24 fwarning("D-Bus handling is disabled in Firejail configuration file\n");
25 return; 25 return;
@@ -43,6 +43,9 @@ void dbus_session_disable(void) {
43 free(path); 43 free(path);
44 free(env_var); 44 free(env_var);
45 45
46 // blacklist also system D-Bus socket
47 disable_file_or_dir("/run/dbus/system_bus_socket");
48
46 // look for a possible abstract unix socket 49 // look for a possible abstract unix socket
47 50
48 // --net=none 51 // --net=none
diff --git a/src/firejail/firejail.h b/src/firejail/firejail.h
index 2e04084e3..e0f3a6a16 100644
--- a/src/firejail/firejail.h
+++ b/src/firejail/firejail.h
@@ -782,6 +782,6 @@ void set_x11_run_file(pid_t pid, int display);
782void set_profile_run_file(pid_t pid, const char *fname); 782void set_profile_run_file(pid_t pid, const char *fname);
783 783
784// dbus.c 784// dbus.c
785void dbus_session_disable(void); 785void dbus_disable(void);
786 786
787#endif 787#endif
diff --git a/src/firejail/fs.c b/src/firejail/fs.c
index f9d968427..bf7c0a4b2 100644
--- a/src/firejail/fs.c
+++ b/src/firejail/fs.c
@@ -27,7 +27,11 @@
27#include <glob.h> 27#include <glob.h>
28#include <dirent.h> 28#include <dirent.h>
29#include <errno.h> 29#include <errno.h>
30
30#include <fcntl.h> 31#include <fcntl.h>
32#ifndef O_PATH
33# define O_PATH 010000000
34#endif
31 35
32#define MAX_BUF 4096 36#define MAX_BUF 4096
33#define EMPTY_STRING ("") 37#define EMPTY_STRING ("")
diff --git a/src/firejail/fs_home.c b/src/firejail/fs_home.c
index e35bf073d..b44d09acc 100644
--- a/src/firejail/fs_home.c
+++ b/src/firejail/fs_home.c
@@ -22,7 +22,6 @@
22#include <linux/limits.h> 22#include <linux/limits.h>
23#include <glob.h> 23#include <glob.h>
24#include <dirent.h> 24#include <dirent.h>
25#include <fcntl.h>
26#include <errno.h> 25#include <errno.h>
27#include <sys/stat.h> 26#include <sys/stat.h>
28#include <sys/types.h> 27#include <sys/types.h>
@@ -31,6 +30,11 @@
31#include <grp.h> 30#include <grp.h>
32//#include <ftw.h> 31//#include <ftw.h>
33 32
33#include <fcntl.h>
34#ifndef O_PATH
35# define O_PATH 010000000
36#endif
37
34static void skel(const char *homedir, uid_t u, gid_t g) { 38static void skel(const char *homedir, uid_t u, gid_t g) {
35 char *fname; 39 char *fname;
36 40
diff --git a/src/firejail/fs_whitelist.c b/src/firejail/fs_whitelist.c
index d128065d3..bce44b9e5 100644
--- a/src/firejail/fs_whitelist.c
+++ b/src/firejail/fs_whitelist.c
@@ -24,9 +24,13 @@
24#include <fnmatch.h> 24#include <fnmatch.h>
25#include <glob.h> 25#include <glob.h>
26#include <dirent.h> 26#include <dirent.h>
27#include <fcntl.h>
28#include <errno.h> 27#include <errno.h>
29 28
29#include <fcntl.h>
30#ifndef O_PATH
31# define O_PATH 010000000
32#endif
33
30// mountinfo functionality test; 34// mountinfo functionality test;
31// 1. enable TEST_MOUNTINFO definition 35// 1. enable TEST_MOUNTINFO definition
32// 2. run firejail --whitelist=/any/directory 36// 2. run firejail --whitelist=/any/directory
diff --git a/src/firejail/mountinfo.c b/src/firejail/mountinfo.c
index 0717b2044..7369ad247 100644
--- a/src/firejail/mountinfo.c
+++ b/src/firejail/mountinfo.c
@@ -19,7 +19,11 @@
19*/ 19*/
20 20
21#include "firejail.h" 21#include "firejail.h"
22
22#include <fcntl.h> 23#include <fcntl.h>
24#ifndef O_PATH
25# define O_PATH 010000000
26#endif
23 27
24#define MAX_BUF 4096 28#define MAX_BUF 4096
25 29
diff --git a/src/firejail/pulseaudio.c b/src/firejail/pulseaudio.c
index 26beaf35a..e3f237b8e 100644
--- a/src/firejail/pulseaudio.c
+++ b/src/firejail/pulseaudio.c
@@ -24,7 +24,11 @@
24#include <sys/mount.h> 24#include <sys/mount.h>
25#include <dirent.h> 25#include <dirent.h>
26#include <sys/wait.h> 26#include <sys/wait.h>
27
27#include <fcntl.h> 28#include <fcntl.h>
29#ifndef O_PATH
30# define O_PATH 010000000
31#endif
28 32
29// disable pulseaudio socket 33// disable pulseaudio socket
30void pulseaudio_disable(void) { 34void pulseaudio_disable(void) {
diff --git a/src/firejail/sandbox.c b/src/firejail/sandbox.c
index 101a16d00..9f0a5f25c 100644
--- a/src/firejail/sandbox.c
+++ b/src/firejail/sandbox.c
@@ -923,7 +923,7 @@ int sandbox(void* sandbox_arg) {
923 // Session D-BUS 923 // Session D-BUS
924 //**************************** 924 //****************************
925 if (arg_nodbus) 925 if (arg_nodbus)
926 dbus_session_disable(); 926 dbus_disable();
927 927
928 928
929 //**************************** 929 //****************************
diff --git a/src/firejail/util.c b/src/firejail/util.c
index 3e2cd13d5..fff0bbf2f 100644
--- a/src/firejail/util.c
+++ b/src/firejail/util.c
@@ -29,7 +29,11 @@
29#include <sys/ioctl.h> 29#include <sys/ioctl.h>
30#include <termios.h> 30#include <termios.h>
31#include <sys/wait.h> 31#include <sys/wait.h>
32
32#include <fcntl.h> 33#include <fcntl.h>
34#ifndef O_PATH
35# define O_PATH 010000000
36#endif
33 37
34#define MAX_GROUPS 1024 38#define MAX_GROUPS 1024
35#define MAXBUF 4098 39#define MAXBUF 4098
diff --git a/src/firejail/x11.c b/src/firejail/x11.c
index b0ed10b30..9d821d980 100644
--- a/src/firejail/x11.c
+++ b/src/firejail/x11.c
@@ -31,7 +31,11 @@
31#include <sys/wait.h> 31#include <sys/wait.h>
32#include <errno.h> 32#include <errno.h>
33#include <limits.h> 33#include <limits.h>
34
34#include <fcntl.h> 35#include <fcntl.h>
36#ifndef O_PATH
37# define O_PATH 010000000
38#endif
35 39
36 40
37// Parse the DISPLAY environment variable and return a display number. 41// Parse the DISPLAY environment variable and return a display number.
diff --git a/src/man/firejail.txt b/src/man/firejail.txt
index 1b56dedcd..8f6948ef4 100644
--- a/src/man/firejail.txt
+++ b/src/man/firejail.txt
@@ -1107,9 +1107,11 @@ $ nc dict.org 2628
1107.br 1107.br
1108.TP 1108.TP
1109\fB\-\-nodbus 1109\fB\-\-nodbus
1110Disable D-Bus access. Only the regular UNIX socket is handled by this command. To 1110Disable D-Bus access (both system and session buses). Only the regular
1111disable the abstract socket you would need to request a new network namespace using 1111UNIX sockets are handled by this command. To disable the abstract
1112\-\-net command. Another option is to remove unix from \-\-protocol set. 1112sockets you would need to request a new network namespace using
1113\-\-net command. Another option is to remove unix from \-\-protocol
1114set.
1113.br 1115.br
1114 1116
1115.br 1117.br