| Commit message (Collapse) | Author | Age |
|\
| |
| | |
steam.profile: allow "${HOME}/.prey"
|
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
The directory is used by the Linux binary for Prey (2006), available at https://icculus.org/prey.
Not whitelisting the directory results in the game failing to launch:
found DLL in pak file: /home/user/.steam/steamapps/common/Prey 2006/base/game01.pk4/gamex86.so
copy gamex86.so to /home/user/.prey/base/gamex86.so
dlopen '/home/user/.prey/base/gamex86.so' failed: /home/user/.prey/base/gamex86.so: failed to map segment from shared object
|
|\ \
| |/
|/| |
Add songrec
|
| |
| |
| |
| |
| |
| |
| | |
It is a Rust application using Cargo, so harden based on common supply
chain attacks seen.
https://github.com/marin-m/SongRec
|
| | |
|
| | |
|
| | |
|
| | |
|
| |
| |
| |
| | |
Relates to #4946.
|
| |
| |
| |
| |
| |
| |
| |
| |
| | |
Put it in a similar order to 0.9.68: features, modifs/reworks, bugfixes,
ci, docs, new profiles.
See commit 5fbc1cd50 ("RELNOTES: sort items by category", 2022-02-05).
Misc: The last paragraph of that commit message is wrong; just ignore
it.
|
| |
| |
| |
| |
| |
| | |
This amends commit 481321881 ("merges", 2022-03-05).
Relates to #4985 #4990 #5011.
|
|\ \
| | |
| | | |
Electron app fixes
|
| | | |
|
| | | |
|
| | |
| | |
| | |
| | | |
follow-up to fdee4dc1326bb2d5ce90ef2a0410dccba56beb70
|
| | | |
|
|/ /
| |
| |
| | |
remove all duplicate entries
|
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
Bumps [actions/checkout](https://github.com/actions/checkout) from 2.4.0 to 3.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/ec3a7ce113134d7a93b817d10a8272cb61118579...a12a3943b4bdde767164f792f33f40b04645d846)
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
|
|\ \ |
|
| |\ \
| | | |
| | | | |
drop redundant ignore in chromium-based browsers
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | | |
|
|/ / / |
|
|\ \ \
| | | |
| | | | |
whitelist restructuring
|
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
Check mountids while creating path of a new mount target.
If the mountid differs from the top level directory (tmpfs)
mountid, this proves an earlier whitelist command.
It is important to note though that this check is not exhaustive,
as besides nested whitelist commands there are also nested
top level directories. So a user could run:
firejail --whitelist=/a/b --whitelist=/a/b/c where both
a and b are (whitelist) top level directories. Such a command
may result in b and c sharing the filesystem and hence mountid.
In this case the nested nature of the whitelist commands
will go unnoticed.
A more rigorous version will probably need to apply some
sorting to the whitelist command, possibly by means of
glob(3).
|
| | | |
| | | |
| | | |
| | | | |
some cleanup, simplify extending the code (for example adding additional members to the TopDir struct)
|
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
as functions operate on a file descriptor
it should be safe to remove them; this
sets the stage for improvements to the
whitelist code
|
|\ \ \ \
| |_|/ /
|/| | | |
Add ability to disable user profiles at compile time.
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
* add opera-developer to firecfg
* add opera-developer
* fix typo
* add configs for opera-developer
* Create opera-developer.profile
* fixes for opera-developer
* fix for opera-developer
|
| | | |
| | | |
| | | |
| | | |
| | | | |
* harden opera-beta
* harden opera
|
| | | |
| | | |
| | | |
| | | |
| | | | |
* geary fixes
* comment ipc-namespace
|
| |/ /
|/| |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 1.1.2 to 1.1.3.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/d39d5d5c9707b926d517b1b292905ef4c03aa777...75f07e7ab2ee63cba88752d8c696324e4df67466)
---
updated-dependencies:
- dependency-name: github/codeql-action
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
|
| | | |
|
| | | |
|
| | | |
|
| | | |
|