aboutsummaryrefslogtreecommitdiffstats
path: root/src/firejail/firejail.h
diff options
context:
space:
mode:
Diffstat (limited to 'src/firejail/firejail.h')
-rw-r--r--src/firejail/firejail.h4
1 files changed, 3 insertions, 1 deletions
diff --git a/src/firejail/firejail.h b/src/firejail/firejail.h
index f4a176caf..661073730 100644
--- a/src/firejail/firejail.h
+++ b/src/firejail/firejail.h
@@ -237,6 +237,7 @@ extern int arg_rlimit_nproc; // rlimit nproc
237extern int arg_rlimit_fsize; // rlimit fsize 237extern int arg_rlimit_fsize; // rlimit fsize
238extern int arg_rlimit_sigpending;// rlimit sigpending 238extern int arg_rlimit_sigpending;// rlimit sigpending
239extern int arg_nogroups; // disable supplementary groups 239extern int arg_nogroups; // disable supplementary groups
240extern int arg_nonewprivs; // set the NO_NEW_PRIVS prctl
240extern int arg_noroot; // create a new user namespace and disable root user 241extern int arg_noroot; // create a new user namespace and disable root user
241extern int arg_netfilter; // enable netfilter 242extern int arg_netfilter; // enable netfilter
242extern int arg_netfilter6; // enable netfilter6 243extern int arg_netfilter6; // enable netfilter6
@@ -565,7 +566,8 @@ void sandboxfs(int op, pid_t pid, const char *patqh);
565#define CFG_SECCOMP 5 566#define CFG_SECCOMP 5
566#define CFG_NETWORK 6 567#define CFG_NETWORK 6
567#define CFG_RESTRICTED_NETWORK 7 568#define CFG_RESTRICTED_NETWORK 7
568#define CFG_MAX 8 // this should always be the last entry 569#define CFG_FORCE_NONEWPRIVS 8
570#define CFG_MAX 9 // this should always be the last entry
569int checkcfg(int val); 571int checkcfg(int val);
570 572
571// fs_rdwr.c 573// fs_rdwr.c