aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--README41
-rw-r--r--RELNOTES5
-rwxr-xr-xconfigure19
-rw-r--r--configure.ac2
-rw-r--r--src/firejail/checkcfg.c2
5 files changed, 56 insertions, 13 deletions
diff --git a/README b/README
index 522fdc34a..7310d22da 100644
--- a/README
+++ b/README
@@ -109,6 +109,7 @@ Amin Vakil (https://github.com/aminvakil)
109 - whois profile fix 109 - whois profile fix
110 - added profile for strawberry 110 - added profile for strawberry
111 - w3m profile fix 111 - w3m profile fix
112 - disable seccomp in wireshark profile
112Andreas Hunkeler (https://github.com/Karneades) 113Andreas Hunkeler (https://github.com/Karneades)
113 - Add profile for offical Linux Teams application 114 - Add profile for offical Linux Teams application
114Andrey Alekseenko (https://github.com/al42and) 115Andrey Alekseenko (https://github.com/al42and)
@@ -203,6 +204,7 @@ Bundy01 (https://github.com/Bundy01)
203 - fixup geary 204 - fixup geary
204 - add gradio profile 205 - add gradio profile
205 - update virtualbox.profile 206 - update virtualbox.profile
207 - Quodlibet profile
206BytesTuner (https://github.com/BytesTuner) 208BytesTuner (https://github.com/BytesTuner)
207 - provided keepassxc profile 209 - provided keepassxc profile
208caoliver (https://github.com/caoliver) 210caoliver (https://github.com/caoliver)
@@ -435,6 +437,8 @@ hamzadis (https://github.com/hamzadis)
435 - added --overlay-named=name and --overlay-path=path 437 - added --overlay-named=name and --overlay-path=path
436Hans-Christoph Steiner (https://github.com/eighthave) 438Hans-Christoph Steiner (https://github.com/eighthave)
437 - added xournal profile 439 - added xournal profile
440Harald Kubota (https://github.com/haraldkubota)
441 - zsh completion
438hawkey116477 (https://github.com/hawkeye116477) 442hawkey116477 (https://github.com/hawkeye116477)
439 - added Waterfox profile 443 - added Waterfox profile
440 - updated Cyberfox profile 444 - updated Cyberfox profile
@@ -520,6 +524,7 @@ Jose Riha (https://github.com/jose1711)
520 - Add davfs2 secrets file to blacklist 524 - Add davfs2 secrets file to blacklist
521 - Add profile for udiskie 525 - Add profile for udiskie
522 - fix udiskie.profile 526 - fix udiskie.profile
527 - improve hints for allowing browser access to Gnome extensions connector
523jrabe (https://github.com/jrabe) 528jrabe (https://github.com/jrabe)
524 - disallow access to kdbx files 529 - disallow access to kdbx files
525 - Epiphany profile 530 - Epiphany profile
@@ -555,6 +560,7 @@ Kishore96in (https://github.com/Kishore96in)
555 - jitsi-meet-desktop profile 560 - jitsi-meet-desktop profile
556 - konversatin profile fix 561 - konversatin profile fix
557 - added Neochat profile 562 - added Neochat profile
563 - added whitelist-1793-workaround.inc
558KOLANICH (https://github.com/KOLANICH) 564KOLANICH (https://github.com/KOLANICH)
559 - added symlink fixer fix_private-bin.py in contrib section 565 - added symlink fixer fix_private-bin.py in contrib section
560 - update fix_private-bin.py 566 - update fix_private-bin.py
@@ -610,6 +616,8 @@ Mattias Wadman (https://github.com/wader)
610 - seccomp errno filter support 616 - seccomp errno filter support
611Matthew Gyurgyik (https://github.com/pyther) 617Matthew Gyurgyik (https://github.com/pyther)
612 - rpm spec and several fixes 618 - rpm spec and several fixes
619Matthew Cline (https://github.com/matthew-cline)
620 - steam profile and dropbox profile fixes
613matu3ba (https://github.com/matu3ba) 621matu3ba (https://github.com/matu3ba)
614 - evince hardening, dbus removed 622 - evince hardening, dbus removed
615 - fix dia profile 623 - fix dia profile
@@ -649,12 +657,20 @@ Nick Fox (https://github.com/njfox)
649 - fix wire-desktop.profile on arch 657 - fix wire-desktop.profile on arch
650NickMolloy (https://github.com/NickMolloy) 658NickMolloy (https://github.com/NickMolloy)
651 - ARP address length fix 659 - ARP address length fix
660Nico (https://github.com/dr460nf1r3)
661 - added FireDragon profile
662Nicola Davide Mannarelli (https://github.com/nidamanx)
663 - fix "Could not create AF_NETLINK socket"
664 - added nextcloud profiles
665 - Firefox, KeepassXC, Telegram fixes
652Niklas Haas (https://github.com/haasn) 666Niklas Haas (https://github.com/haasn)
653 - blacklisting for keybase.io's client 667 - blacklisting for keybase.io's client
654Niklas Goerke (https://github.com/Niklas974) 668Niklas Goerke (https://github.com/Niklas974)
655 - update QOwnNotes profile 669 - update QOwnNotes profile
656Nikos Chantziaras (https://github.com/realnc) 670Nikos Chantziaras (https://github.com/realnc)
657 - fix audio support for Discord 671 - fix audio support for Discord
672nolanl (https://github.com/nolanl)
673 - added localtime to signal-desktop's profile
658nyancat18 (https://github.com/nyancat18) 674nyancat18 (https://github.com/nyancat18)
659 - added ardour4, dooble, karbon, krita profiles 675 - added ardour4, dooble, karbon, krita profiles
660Ondra Nekola (https://github.com/satai) 676Ondra Nekola (https://github.com/satai)
@@ -702,6 +718,8 @@ Petter Reinholdtsen (pere@hungry.com)
702PharmaceuticalCobweb (https://github.com/PharmaceuticalCobweb) 718PharmaceuticalCobweb (https://github.com/PharmaceuticalCobweb)
703 - fix quiterss profile 719 - fix quiterss profile
704 - added profile for gnome-ring 720 - added profile for gnome-ring
721pholodniak (https://github.com/pholodniak)
722 - profstats fixes
705pianoslum (https://github.com/pianoslum) 723pianoslum (https://github.com/pianoslum)
706 - nodbus breaking evince two-page-view warning 724 - nodbus breaking evince two-page-view warning
707pirate486743186 (https://github.com/pirate486743186) 725pirate486743186 (https://github.com/pirate486743186)
@@ -709,6 +727,17 @@ pirate486743186 (https://github.com/pirate486743186)
709 - mpsyt profile 727 - mpsyt profile
710 - fix youtube-dl and mpv 728 - fix youtube-dl and mpv
711 - fix gnome-mpv profile 729 - fix gnome-mpv profile
730 - fix gunzip profile
731 - reorganizing youtube-viewers
732 - fix pluma profile
733 - whitelist /var/lib/aspell
734 - mcomix fixes
735 - fixing engrampa profile
736 - adding qcomicbook and pipe-viewer in disable-programs
737 - newsboat/newsbeuter profiles
738 - fix atril profile
739 - rtv profile
740 - reorganizing links browsers
712Pixel Fairy (https://github.com/xahare) 741Pixel Fairy (https://github.com/xahare)
713 - added fjclip.py, fjdisplay.py and fjresize.py in contrib section 742 - added fjclip.py, fjdisplay.py and fjresize.py in contrib section
714PizzaDude (https://github.com/pizzadude) 743PizzaDude (https://github.com/pizzadude)
@@ -745,6 +774,7 @@ Rahul Golam (https://github.com/technoLord)
745RandomVoid (https://github.com/RandomVoid) 774RandomVoid (https://github.com/RandomVoid)
746 - fix building C# projects in Godot 775 - fix building C# projects in Godot
747 - fix Lutris profile 776 - fix Lutris profile
777 - fix running games with enabled Feral GameMode in Lutris
748Raphaël Droz (https://github.com/drzraf) 778Raphaël Droz (https://github.com/drzraf)
749 - zoom profile fixes 779 - zoom profile fixes
750realaltffour (https://github.com/realaltffour) 780realaltffour (https://github.com/realaltffour)
@@ -786,6 +816,8 @@ rusty-snake (https://github.com/rusty-snake)
786 - some typo fixes 816 - some typo fixes
787 - added profile templates 817 - added profile templates
788 - added sort.py to contrib 818 - added sort.py to contrib
819sak96 (https://github.com/sak96)
820 - discord profile fixes
789Salvo 'LtWorf' Tomaselli (https://github.com/ltworf) 821Salvo 'LtWorf' Tomaselli (https://github.com/ltworf)
790 - fixed ktorrent profile 822 - fixed ktorrent profile
791sarneaud (https://github.com/sarneaud) 823sarneaud (https://github.com/sarneaud)
@@ -814,6 +846,8 @@ sinkuu (https://github.com/sinkuu)
814 - fix symlink invocation for programs placing symlinks in $PATH 846 - fix symlink invocation for programs placing symlinks in $PATH
815Simo Piiroinen (https://github.com/spiiroin) 847Simo Piiroinen (https://github.com/spiiroin)
816 - Jolla/SailfishOS patches 848 - Jolla/SailfishOS patches
849slowpeek (https://github.com/slowpeek)
850 - refine appimage example in docs
817smitsohu (https://github.com/smitsohu) 851smitsohu (https://github.com/smitsohu)
818 - read-only kde4 services directory 852 - read-only kde4 services directory
819 - enhanced mediathekview profile 853 - enhanced mediathekview profile
@@ -939,6 +973,10 @@ Topi Miettinen (https://github.com/topimiettinen)
939 - improve loading of seccomp filter and memory-deny-write-execute feature 973 - improve loading of seccomp filter and memory-deny-write-execute feature
940 - private-lib feature 974 - private-lib feature
941 - make --nodbus block also system D-Bus socket 975 - make --nodbus block also system D-Bus socket
976Ted Robertson (https://github.com/tredondo)
977 - webstorm profile fixes
978 - added bcompare profile
979 - various documentation fixes
942user1024 (user1024@tut.by) 980user1024 (user1024@tut.by)
943 - electron profile whitelisting 981 - electron profile whitelisting
944 - fixed Rocket.Chat profile 982 - fixed Rocket.Chat profile
@@ -1003,6 +1041,9 @@ Vladimir Schowalter (https://github.com/VladimirSchowalter20)
1003 - apparmor profile enhancements 1041 - apparmor profile enhancements
1004 - various KDE profile enhancements 1042 - various KDE profile enhancements
1005 read-only kde5 services directory 1043 read-only kde5 services directory
1044Vladislav Nepogodin (https://github.com/vnepogodin)
1045 - added Librewolf profiles
1046 - added Sway profile
1006xee5ch (https://github.com/xee5ch) 1047xee5ch (https://github.com/xee5ch)
1007 - skypeforlinux profile 1048 - skypeforlinux profile
1008Ypnose (https://github.com/Ypnose) 1049Ypnose (https://github.com/Ypnose)
diff --git a/RELNOTES b/RELNOTES
index 790b72557..9a5f165cd 100644
--- a/RELNOTES
+++ b/RELNOTES
@@ -1,6 +1,7 @@
1firejail (0.9.65) baseline; urgency=low 1firejail (0.9.65) baseline; urgency=low
2 * deprecated --audit options, relpaced by jailtest 2 * deprecated --audit options, relpaced by jailcheck utility
3 * deprecated follow-symlink-as-user from firejail.config 3 * deprecated follow-symlink-as-user from firejail.config
4 * rename --noautopulse to keep-config-pulse
4 * filtering environment variables 5 * filtering environment variables
5 * zsh completion 6 * zsh completion
6 * command line: --mkdir, --mkfile 7 * command line: --mkdir, --mkfile
@@ -33,7 +34,7 @@ firejail (0.9.65) baseline; urgency=low
33 * neverball-wrapper, neverputt-wrapper, supertuxkart-wrapper, neochat, 34 * neverball-wrapper, neverputt-wrapper, supertuxkart-wrapper, neochat,
34 * cargo, LibreCAD, blobby, funnyboat, pipe-viewer, gtk-pipe-viewer 35 * cargo, LibreCAD, blobby, funnyboat, pipe-viewer, gtk-pipe-viewer
35 * links2, xlinks2 36 * links2, xlinks2
36 -- netblue30 <netblue30@yahoo.com> Tue, 9 Feb 2021 09:00:00 -0500 37 -- netblue30 <netblue30@yahoo.com> Wed, 2 Jun 2021 09:00:00 -0500
37 38
38firejail (0.9.64.4) baseline; urgency=low 39firejail (0.9.64.4) baseline; urgency=low
39 * disabled overlayfs, pending multiple fixes (CVE-2021-26910) 40 * disabled overlayfs, pending multiple fixes (CVE-2021-26910)
diff --git a/configure b/configure
index f31816599..9162b6c90 100755
--- a/configure
+++ b/configure
@@ -1,6 +1,6 @@
1#! /bin/sh 1#! /bin/sh
2# Guess values for system-dependent variables and create Makefiles. 2# Guess values for system-dependent variables and create Makefiles.
3# Generated by GNU Autoconf 2.69 for firejail 0.9.65. 3# Generated by GNU Autoconf 2.69 for firejail 0.9.66rc1.
4# 4#
5# Report bugs to <netblue30@protonmail.com>. 5# Report bugs to <netblue30@protonmail.com>.
6# 6#
@@ -580,8 +580,8 @@ MAKEFLAGS=
580# Identity of this package. 580# Identity of this package.
581PACKAGE_NAME='firejail' 581PACKAGE_NAME='firejail'
582PACKAGE_TARNAME='firejail' 582PACKAGE_TARNAME='firejail'
583PACKAGE_VERSION='0.9.65' 583PACKAGE_VERSION='0.9.66rc1'
584PACKAGE_STRING='firejail 0.9.65' 584PACKAGE_STRING='firejail 0.9.66rc1'
585PACKAGE_BUGREPORT='netblue30@protonmail.com' 585PACKAGE_BUGREPORT='netblue30@protonmail.com'
586PACKAGE_URL='https://firejail.wordpress.com' 586PACKAGE_URL='https://firejail.wordpress.com'
587 587
@@ -1299,7 +1299,7 @@ if test "$ac_init_help" = "long"; then
1299 # Omit some internal or obsolete options to make the list less imposing. 1299 # Omit some internal or obsolete options to make the list less imposing.
1300 # This message is too long to be a string in the A/UX 3.1 sh. 1300 # This message is too long to be a string in the A/UX 3.1 sh.
1301 cat <<_ACEOF 1301 cat <<_ACEOF
1302\`configure' configures firejail 0.9.65 to adapt to many kinds of systems. 1302\`configure' configures firejail 0.9.66rc1 to adapt to many kinds of systems.
1303 1303
1304Usage: $0 [OPTION]... [VAR=VALUE]... 1304Usage: $0 [OPTION]... [VAR=VALUE]...
1305 1305
@@ -1361,7 +1361,7 @@ fi
1361 1361
1362if test -n "$ac_init_help"; then 1362if test -n "$ac_init_help"; then
1363 case $ac_init_help in 1363 case $ac_init_help in
1364 short | recursive ) echo "Configuration of firejail 0.9.65:";; 1364 short | recursive ) echo "Configuration of firejail 0.9.66rc1:";;
1365 esac 1365 esac
1366 cat <<\_ACEOF 1366 cat <<\_ACEOF
1367 1367
@@ -1481,7 +1481,7 @@ fi
1481test -n "$ac_init_help" && exit $ac_status 1481test -n "$ac_init_help" && exit $ac_status
1482if $ac_init_version; then 1482if $ac_init_version; then
1483 cat <<\_ACEOF 1483 cat <<\_ACEOF
1484firejail configure 0.9.65 1484firejail configure 0.9.66rc1
1485generated by GNU Autoconf 2.69 1485generated by GNU Autoconf 2.69
1486 1486
1487Copyright (C) 2012 Free Software Foundation, Inc. 1487Copyright (C) 2012 Free Software Foundation, Inc.
@@ -1783,7 +1783,7 @@ cat >config.log <<_ACEOF
1783This file contains any messages produced by compilers while 1783This file contains any messages produced by compilers while
1784running configure, to aid debugging if configure makes a mistake. 1784running configure, to aid debugging if configure makes a mistake.
1785 1785
1786It was created by firejail $as_me 0.9.65, which was 1786It was created by firejail $as_me 0.9.66rc1, which was
1787generated by GNU Autoconf 2.69. Invocation command line was 1787generated by GNU Autoconf 2.69. Invocation command line was
1788 1788
1789 $ $0 $@ 1789 $ $0 $@
@@ -4910,7 +4910,7 @@ cat >>$CONFIG_STATUS <<\_ACEOF || ac_write_fail=1
4910# report actual input values of CONFIG_FILES etc. instead of their 4910# report actual input values of CONFIG_FILES etc. instead of their
4911# values after options handling. 4911# values after options handling.
4912ac_log=" 4912ac_log="
4913This file was extended by firejail $as_me 0.9.65, which was 4913This file was extended by firejail $as_me 0.9.66rc1, which was
4914generated by GNU Autoconf 2.69. Invocation command line was 4914generated by GNU Autoconf 2.69. Invocation command line was
4915 4915
4916 CONFIG_FILES = $CONFIG_FILES 4916 CONFIG_FILES = $CONFIG_FILES
@@ -4964,7 +4964,7 @@ _ACEOF
4964cat >>$CONFIG_STATUS <<_ACEOF || ac_write_fail=1 4964cat >>$CONFIG_STATUS <<_ACEOF || ac_write_fail=1
4965ac_cs_config="`$as_echo "$ac_configure_args" | sed 's/^ //; s/[\\""\`\$]/\\\\&/g'`" 4965ac_cs_config="`$as_echo "$ac_configure_args" | sed 's/^ //; s/[\\""\`\$]/\\\\&/g'`"
4966ac_cs_version="\\ 4966ac_cs_version="\\
4967firejail config.status 0.9.65 4967firejail config.status 0.9.66rc1
4968configured by $0, generated by GNU Autoconf 2.69, 4968configured by $0, generated by GNU Autoconf 2.69,
4969 with options \\"\$ac_cs_config\\" 4969 with options \\"\$ac_cs_config\\"
4970 4970
@@ -5559,6 +5559,7 @@ if test -n "$ac_unrecognized_opts" && test "$enable_option_checking" != no; then
5559$as_echo "$as_me: WARNING: unrecognized options: $ac_unrecognized_opts" >&2;} 5559$as_echo "$as_me: WARNING: unrecognized options: $ac_unrecognized_opts" >&2;}
5560fi 5560fi
5561 5561
5562
5562cat <<EOF 5563cat <<EOF
5563 5564
5564Configuration options: 5565Configuration options:
diff --git a/configure.ac b/configure.ac
index 0eb616355..f37db5926 100644
--- a/configure.ac
+++ b/configure.ac
@@ -12,7 +12,7 @@
12# 12#
13 13
14AC_PREREQ([2.68]) 14AC_PREREQ([2.68])
15AC_INIT([firejail],[0.9.65],[netblue30@protonmail.com],[],[https://firejail.wordpress.com]) 15AC_INIT([firejail],[0.9.66rc1],[netblue30@protonmail.com],[],[https://firejail.wordpress.com])
16AC_CONFIG_SRCDIR([src/firejail/main.c]) 16AC_CONFIG_SRCDIR([src/firejail/main.c])
17 17
18AC_CONFIG_MACRO_DIR([m4]) 18AC_CONFIG_MACRO_DIR([m4])
diff --git a/src/firejail/checkcfg.c b/src/firejail/checkcfg.c
index cb087d395..6726abdc8 100644
--- a/src/firejail/checkcfg.c
+++ b/src/firejail/checkcfg.c
@@ -294,7 +294,7 @@ errout:
294 294
295void print_compiletime_support(void) { 295void print_compiletime_support(void) {
296 printf("Compile time support:\n"); 296 printf("Compile time support:\n");
297 printf("\t- Always force nonewprivs support is %s\n", 297 printf("\t- always force nonewprivs support is %s\n",
298#ifdef HAVE_FORCE_NONEWPRIVS 298#ifdef HAVE_FORCE_NONEWPRIVS
299 "enabled" 299 "enabled"
300#else 300#else