aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--etc/brave.profile3
-rw-r--r--etc/disable-common.inc3
-rw-r--r--src/firejail/fs.c3
3 files changed, 8 insertions, 1 deletions
diff --git a/etc/brave.profile b/etc/brave.profile
index 29130ea5f..35c59f5a3 100644
--- a/etc/brave.profile
+++ b/etc/brave.profile
@@ -25,5 +25,8 @@ whitelist ${HOME}/.config/brave
25whitelist ${HOME}/.config/brave-flags.conf 25whitelist ${HOME}/.config/brave-flags.conf
26whitelist ${HOME}/.gnupg 26whitelist ${HOME}/.gnupg
27 27
28# Brave sandbox needs read access to /proc/config.gz
29noblacklist /proc/config.gz
30
28# Redirect 31# Redirect
29include chromium-common.profile 32include chromium-common.profile
diff --git a/etc/disable-common.inc b/etc/disable-common.inc
index 137e4f8bd..16f231108 100644
--- a/etc/disable-common.inc
+++ b/etc/disable-common.inc
@@ -452,3 +452,6 @@ blacklist ${HOME}/Mail
452blacklist ${HOME}/mail 452blacklist ${HOME}/mail
453blacklist ${HOME}/postponed 453blacklist ${HOME}/postponed
454blacklist ${HOME}/sent 454blacklist ${HOME}/sent
455
456# kernel configuration
457blacklist /proc/config.gz
diff --git a/src/firejail/fs.c b/src/firejail/fs.c
index 3ba968004..316057ec5 100644
--- a/src/firejail/fs.c
+++ b/src/firejail/fs.c
@@ -642,7 +642,8 @@ void fs_proc_sys_dev_boot(void) {
642 // various /proc files 642 // various /proc files
643 disable_file(BLACKLIST_FILE, "/proc/irq"); 643 disable_file(BLACKLIST_FILE, "/proc/irq");
644 disable_file(BLACKLIST_FILE, "/proc/bus"); 644 disable_file(BLACKLIST_FILE, "/proc/bus");
645 disable_file(BLACKLIST_FILE, "/proc/config.gz"); 645 // move /proc/config.gz to disable-common.inc
646 //disable_file(BLACKLIST_FILE, "/proc/config.gz");
646 disable_file(BLACKLIST_FILE, "/proc/sched_debug"); 647 disable_file(BLACKLIST_FILE, "/proc/sched_debug");
647 disable_file(BLACKLIST_FILE, "/proc/timer_list"); 648 disable_file(BLACKLIST_FILE, "/proc/timer_list");
648 disable_file(BLACKLIST_FILE, "/proc/timer_stats"); 649 disable_file(BLACKLIST_FILE, "/proc/timer_stats");