aboutsummaryrefslogtreecommitdiffstats
Commit message (Collapse)AuthorAge
* tests: fix check for modules directoryLibravatar Reiner Herrmann2020-08-14
| | | | | 'modules' can also be seen as a sub-directory, e.g. ./powerpc64le-linux-gnu/gio/modules/libgiolibproxy.so
* tests: fix rlimit test for 32bit archsLibravatar Reiner Herrmann2020-08-14
| | | | | On 32bit architectures like armhf, the output was "unlimited" instead of the expected value.
* print errno if char device creation failsLibravatar Reiner Herrmann2020-08-14
| | | | on Ubuntu autopkgtest runs on armhf, /dev/zero creation fails.
* tests: fix false-positive match on modulesLibravatar Reiner Herrmann2020-08-14
| | | | | | The systemd service file ./systemd/system/sysinit.target.wants/systemd-modules-load.service can exist which will lead to a match for "modules", though we are only looking for the modules directory.
* Merge pull request #3583 from kortewegdevries/fixnomacsLibravatar Fred Barclay2020-08-13
|\ | | | | Fix nomacs
| * Fix nomacsLibravatar kortewegdevries2020-08-11
| | | | | | | | | | | | | | | | | | | | ``` Aug 11 16:32:32 korte audit[29004]: SECCOMP auid=1000 uid=1000 gid=1000 ses=2 subj==firejail-default (enforce) pid=29004 comm="nomacs" exe="/usr/bin/nomacs" sig=31 arch=c000003e syscall=9 compat=0 ip=0x7fa2a1cc98c6 code=0x0 ```
* | shutdown option hidepid fixLibravatar smitsohu2020-08-13
| |
* | Merge pull request #3573 from dandelionred/masterLibravatar startx20172020-08-12
|\ \ | | | | | | mkdeb.sh should not use files outside $CODE_DIR
| * | mkdeb.sh should not use files outside $CODE_DIRLibravatar dandelionred2020-08-07
| | |
* | | Merge pull request #3569 from topimiettinen/seccomp-logLibravatar startx20172020-08-12
|\ \ \ | | | | | | | | seccomp: logging
| * | | seccomp: loggingLibravatar Topi Miettinen2020-08-05
| | | | | | | | | | | | | | | | | | | | | | | | | | | | Allow `log` as an alternative seccomp error action instead of killing or returning an errno code. Signed-off-by: Topi Miettinen <toiwoton@gmail.com>
* | | | Added youtube-viewer profile with Gtk frontends (#3542)Libravatar kortewegdevries2020-08-11
| |_|/ |/| | | | | | | | | | | Initial,amend: wrong dir,delete gtk-*,added new files Co-authored-by: kortewegdevries <k0rtic_dv@aol.com>
* | | chroot: expose x11 session if FIREJAIL_CHROOT_X11 is setLibravatar smitsohu2020-08-10
| | | | | | | | | | | | add check so that environment variable FIREJAIL_CHROOT_X11 can be used to mount /tmp/.X11-unix into the chroot; issue #3568
* | | mount sandbox lib directory ro,nosuid,nodevLibravatar smitsohu2020-08-08
| | |
* | | fix for older compilers (gcc 4.9.2, Debian 8)Libravatar netblue302020-08-08
| | |
* | | annotate some functions as non-returning (#3574)Libravatar Reiner Herrmann2020-08-08
| | |
* | | update release notesLibravatar Reiner Herrmann2020-08-08
| |/ |/|
* | firejail: don't pass command line through shell when redirecting outputLibravatar Reiner Herrmann2020-08-06
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | When redirecting output via --output or --output-stderr, firejail was concatenating all command line arguments into a single string that was passed to a shell. As the arguments were no longer escaped, the shell was able to interpret them. Someone who has control over the command line arguments of the sandboxed application could use this to run arbitrary other commands. Instead of passing it through a shell for piping the output to ftee, the pipeline is now manually created and the processes are executed directly. Fixes: CVE-2020-17368 Reported-by: Tim Starling <tstarling@wikimedia.org>
* | firejail: don't interpret output arguments after end-of-options tagLibravatar Reiner Herrmann2020-08-06
|/ | | | | | | | | | | Firejail was parsing --output and --output-stderr options even after the end-of-options separator ("--"), which would allow someone who has control over command line options of the sandboxed application, to write data to a specified file. Fixes: CVE-2020-17367 Reported-by: Tim Starling <tstarling@wikimedia.org>
* Support to ingore a include foobar.incLibravatar rusty-snake2020-08-04
| | | | closes #1139
* Add profile for otter-browser (#3564)Libravatar kortewegdevries2020-08-04
| | | | | | | * Add profile for otter-browser Initial * private-bin,sorting
* don't run with closed standard streamsLibravatar smitsohu2020-08-03
| | | | | | Ensure that all standard streams are open and we don't inadvertently print to files opened for a different reason; in general we can expect glibc to take care of this, but it doesn't cover the case where a sandbox is started by root. The added code also serves as a fallback. Unrelated: For what it's worth, shift umask call closer to main start, so it runs before lowering privileges and before anything can really go wrong.
* Remove unused dummy source fileLibravatar Reiner Herrmann2020-08-01
|
* fix ordering in vmware.profileLibravatar glitsj162020-07-31
|
* Added git-cola profile (#3560)Libravatar kortewegdevries2020-07-30
| | | | | | | | | | | * Added git-cola profile Initial * Edit private-etc Add alternatives,pki * Add disable-xdg
* Add vmware profile #3526Libravatar Neo000012020-07-30
|
* new profile: gnome-calendarLibravatar rusty-snake2020-07-30
|
* add profile for sushi (#3558)Libravatar rusty-snake2020-07-30
|
* Added lyx profile (#3556)Libravatar kortewegdevries2020-07-30
| | | | | | | | | * Added lyx profile Initial * Rmoved whitelists Make home directory more accessible
* Added minitube profile (#3555)Libravatar kortewegdevries2020-07-30
| | | | | | | | | * Added minitube profile Initial * Second Removed no3d,added novideo
* Added Nuclear profile (#3553)Libravatar kortewegdevries2020-07-30
| | | Initial
* Added mtpaint profile (#3550)Libravatar kortewegdevries2020-07-30
| | | | | | | | | * Added mtpaint profile Initial * Second Remove IPC-namespace,netfilter
* initial /home cleaning: fail gently if home directory is a FUSE mountLibravatar smitsohu2020-07-29
|
* Merge pull request #3521 from smitsohu/join2Libravatar smitsohu2020-07-29
|\ | | | | integrate join(-or-start) with dbus options (partial fix)
| * integrate join(-or-start) with dbus optionsLibravatar smitsohu2020-07-18
| | | | | | | | | | update D-Bus environment variables during join, so that a joining process is able to use D-Bus, too
* | fix Lua in mpv.profileLibravatar glitsj162020-07-28
| | | | | | Fixes for #3554.
* | Added minecraft-launcher profile (#3538)Libravatar kortewegdevries2020-07-27
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | * Added minecraft-launcher-profile Initial * Changed minecraft-launcher profile Added space,tracelog,nodvd * Third Fixed private-etc,added notes about path,java * Sorting
* | fix ordering in xfce4-screenshooter.profileLibravatar glitsj162020-07-26
| |
* | Merge pull request #3547 from kortewegdevries/mtpaintLibravatar rusty-snake2020-07-26
|\ \ | | | | | | Added xfce4-screenshooter profile
| * | Added xfce4-screenshooter profileLibravatar kortewegdevries2020-07-25
| | | | | | | | | | | | Initial,removed common blaclist,add netfilter,private-etc
* | | fix #3551Libravatar rusty-snake2020-07-26
| | |
* | | Merge pull request #3548 from EmilGedda/patch-1Libravatar rusty-snake2020-07-26
|\ \ \ | | | | | | | | fix typo in multicast CIDR
| * | | fix typo in multicast CIDRLibravatar Emil Gedda2020-07-25
|/ / /
* | | Merge pull request #3502 from awelzel/ignore-sigttou-during-stdin-flushLibravatar smitsohu2020-07-25
|\ \ \ | |/ / |/| | Ignore SIGTTOU during flush_stdin()
| * | Ignore SIGTTOU during flush_stdin()Libravatar Arne Welzel2020-07-08
| | | | | | | | | | | | fixes #3500
* | | add newsflash profileLibravatar rusty-snake2020-07-25
| | |
* | | Update virtualbox.profile (#3537)Libravatar Neo000012020-07-24
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | * Update virtualbox.profile * Update virtualbox.profile * Update virtualbox.profile * Update virtualbox.profile * Update virtualbox.profile * Update virtualbox.profile
* | | Merge pull request #3543 from kortewegdevries/github-desktop-patchLibravatar rusty-snake2020-07-24
|\ \ \ | | | | | | | | Github-desktop: Add chroot to seccomp
| * | | Filter seccompLibravatar kortewegdevries2020-07-24
|/ / / | | | | | | | | | Add chroot
* | | fix ordering in freetube.profileLibravatar glitsj162020-07-23
| | |