aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--Makefile2
-rw-r--r--etc/ids.config1
-rw-r--r--etc/inc/disable-common.inc3
-rw-r--r--src/jailcheck/main.c1
4 files changed, 6 insertions, 1 deletions
diff --git a/Makefile b/Makefile
index 53b57a0e1..fdf83beb4 100644
--- a/Makefile
+++ b/Makefile
@@ -362,7 +362,7 @@ scan-build: clean
362 362
363.PHONY: codespell 363.PHONY: codespell
364codespell: clean 364codespell: clean
365 codespell --ignore-regex "UE|creat|shotcut|ether" src test 365 codespell --ignore-regex "UE|creat|doas|shotcut|ether" src test
366 366
367.PHONY: print-env 367.PHONY: print-env
368print-env: 368print-env:
diff --git a/etc/ids.config b/etc/ids.config
index 880ec6ab5..4b75c701c 100644
--- a/etc/ids.config
+++ b/etc/ids.config
@@ -139,6 +139,7 @@ ${HOME}/.local/share/autostart
139/etc/security 139/etc/security
140/etc/selinux 140/etc/selinux
141/etc/shadow* 141/etc/shadow*
142/etc/sudo*.conf
142/etc/sudoers* 143/etc/sudoers*
143/etc/tripwire 144/etc/tripwire
144${HOME}/.config/firejail 145${HOME}/.config/firejail
diff --git a/etc/inc/disable-common.inc b/etc/inc/disable-common.inc
index 4277100ce..ce4f08958 100644
--- a/etc/inc/disable-common.inc
+++ b/etc/inc/disable-common.inc
@@ -416,6 +416,7 @@ blacklist /tmp/ssh-*
416# top secret 416# top secret
417blacklist /.fscrypt 417blacklist /.fscrypt
418blacklist /etc/davfs2/secrets 418blacklist /etc/davfs2/secrets
419blacklist /etc/doas.conf
419blacklist /etc/group+ 420blacklist /etc/group+
420blacklist /etc/group- 421blacklist /etc/group-
421blacklist /etc/gshadow 422blacklist /etc/gshadow
@@ -428,6 +429,8 @@ blacklist /etc/shadow+
428blacklist /etc/shadow- 429blacklist /etc/shadow-
429blacklist /etc/ssh 430blacklist /etc/ssh
430blacklist /etc/ssh/* 431blacklist /etc/ssh/*
432blacklist /etc/sudo*.conf
433blacklist /etc/sudoers*
431blacklist /home/.ecryptfs 434blacklist /home/.ecryptfs
432blacklist /home/.fscrypt 435blacklist /home/.fscrypt
433blacklist ${HOME}/*.kdb 436blacklist ${HOME}/*.kdb
diff --git a/src/jailcheck/main.c b/src/jailcheck/main.c
index 27da309ea..93d334c7a 100644
--- a/src/jailcheck/main.c
+++ b/src/jailcheck/main.c
@@ -120,6 +120,7 @@ int main(int argc, char **argv) {
120 // basic sysfiles 120 // basic sysfiles
121 sysfiles_setup("/etc/shadow"); 121 sysfiles_setup("/etc/shadow");
122 sysfiles_setup("/etc/gshadow"); 122 sysfiles_setup("/etc/gshadow");
123 sysfiles_setup("/usr/bin/doas");
123 sysfiles_setup("/usr/bin/mount"); 124 sysfiles_setup("/usr/bin/mount");
124 sysfiles_setup("/usr/bin/su"); 125 sysfiles_setup("/usr/bin/su");
125 sysfiles_setup("/usr/bin/ksu"); 126 sysfiles_setup("/usr/bin/ksu");